Impact
The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and represents a CWE-306 Improper Authentication flaw. An unauthenticated attacker possessing network access to the T3 or IIOP ports can exploit the flaw, enabling full takeover of the application. Successful exploitation results in complete loss of confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 9.8.
Affected Systems
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0, are part of Oracle Fusion Middleware and are widely deployed in enterprise environments. These two releases are the only ones known to be vulnerable; later revisions are considered fixed.
Risk and Exploitability
The CVSS score of 9.8 ranks this as critical, while the EPSS score of <1% indicates a low probability that the vulnerability will be actively exploited at any time. The flaw is not yet listed in CISA's KEV catalog, but the ability to compromise the system without authentication makes it a high priority target for defensive measures.
OpenCVE Enrichment