Impact
The vulnerability is an unauthorized access flaw in Oracle WebCenter Content that permits unauthenticated actors who can reach the application over HTTP to create, delete, or modify data, jeopardizing both confidentiality and integrity of the content. The weakness is an improper access control flaw identified as CWE-284 and can potentially impact related components due to a scope change.
Affected Systems
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware. Any installation of these versions that is reachable over HTTP is vulnerable.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.7 indicates high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild, but the vulnerability can be exercised remotely without authentication or special conditions, and is not listed in the CISA KEV catalog. Attackers can compromise data confidentiality and integrity, and due to the scope change, adjacent components may also be affected.
OpenCVE Enrichment