Impact
The vulnerability lies in Oracle WebCenter Content’s Content Server component and allows an attacker to execute arbitrary code on the affected system without authentication. By sending a specially crafted HTTP request, a remote attacker can compromise the integrity, confidentiality, and availability of the application, potentially leading to full takeover of the WebCenter Content instance. The weakness is a classic example of improper access control that can lead to remote code execution.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are part of Oracle Fusion Middleware and are used in enterprise content management deployments. The vulnerability impacts only systems that expose the WebCenter Content HTTP interface to the network, as the exploit requires network access to the application port.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical severity, with high effects on confidentiality, integrity, and availability. The EPSS score is below 1%, suggesting that while the likelihood of exploitation at any given time is low, the impact of a successful attack is catastrophic. The vulnerability is listed as not in the CISA KEV catalog, but the exploit path is straightforward – an unauthenticated attacker can trigger the flaw via an HTTP request, so monitoring and patching are essential. Given the ease of exploitation, the risk remains high until the vulnerability is remediated.
OpenCVE Enrichment