Impact
A flaw in Oracle WebCenter Content allows a low‑privileged user with HTTP access to create, delete, or alter critical data. The weakness is a CWE‑284: Improper Access Control, which permits unauthorized data modification. The flaw requires a separate user to provide required interaction, meaning the attacker cannot execute the vulnerability in full automation but can still gain significant confidentiality and integrity loss. Successful exploitation permits the attacker to read, modify, create, or delete critical content within WebCenter Content.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware, and the flaw may also impact other products that rely on the Content Server component.
Risk and Exploitability
The CVSS v3.1 Base score of 8.7 indicates a high severity vulnerability that can allow unauthorized data modification through improper access control (CWE‑284). The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not included in CISA’s KEV catalog. Attackers can exploit the flaw remotely via HTTP; they need low privileges and a cooperating user to interact with the system. Once leveraged, the attacker can read, modify, create, or delete critical data within Oracle WebCenter Content, thereby compromising confidentiality and integrity.
OpenCVE Enrichment