Impact
An insecure privilege handling mechanism in the Content Server component of Oracle WebCenter Content allows a high‑privileged attacker who can reach the server via HTTP to take complete control of the application, thereby compromising confidentiality, integrity, and availability of all data stored and served by the system.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.2 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low, yet non‑zero, likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers need network access to the Content Server’s HTTP interface and must possess or obtain high‑privilege credentials within the application. In practice, the vulnerability is considered easily exploitable once the conditions are met, enabling a takeover of the entire WebCenter Content deployment.
OpenCVE Enrichment