Impact
This vulnerability allows an attacker with low privilege but network access via HTTP to compromise the Oracle WebCenter Content Content Server. Successful exploitation permits reading, inserting, updating, or deleting data, granting full control over accessible content. The flaw is an access control weakness (CWE‑284) that leads to confidentiality compromise and integrity degradation.
Affected Systems
Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0 are affected. The advisory notes that the vulnerability could also impact other Oracle Fusion Middleware products due to a scope change.
Risk and Exploitability
The CVSS base score of 8.5 classifies this as high severity. The EPSS value of less than 1% indicates a low probability of exploitation, and the vulnerability is not catalogued in CISA KEV. The attack vector is network-based, requiring only low privilege and no user interaction, so an internal or compromised host could exploit it if the necessary controls are not in place. No public exploits have been reported.
OpenCVE Enrichment