Impact
This vulnerability in Oracle WebCenter Enterprise Capture, stemming from improper access control (CWE-284), allows an attacker with low privileges who can reach the system via the T3 or IIOP protocols to take over the application. Exploitation results in confidentiality, integrity, and availability impacts, as the attacker can execute arbitrary code within the affected product's context. The CVSS 3.1 base score of 9.9 reflects the severity of this impact.
Affected Systems
Affected vendors and products are Oracle Corporation’s WebCenter Enterprise Capture, specifically versions 12.2.1.4.0 and 14.1.2.0.0. Because the exploitation could affect additional components of the Fusion Middleware stack, the scope may extend beyond the directly listed product.
Risk and Exploitability
Although the EPSS score indicates that exploitation probability is low (under 1%), the vulnerability is highly exploitable due to improper access control (CWE-284) weaknesses, allowing a network‑directed attacker with low privileges to send a crafted payload over the publicly reachable T3 or IIOP channels and execute arbitrary code. The lack of inclusion in the CISA KEV inventory means no publicly reported active exploitation yet, but the high CVSS score and the possibility of scope change advise urgent attention.
OpenCVE Enrichment