Impact
The Oracle WebCenter Content vulnerability allows an attacker who can log onto the infrastructure hosting the application to compromise the service and gain unrestricted read access to all stored content. This local privilege escalation flaw removes proper access controls, enabling the attacker to bypass authentication barriers and access critical data. The weakness lies in insufficient enforcement of authorization checks within the application.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and are commonly deployed in enterprise content management environments.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates moderate to high severity, focusing on confidentiality impact. The EPSS score is less than 1%, indicating a low likelihood of exploitation at the time of analysis, but it remains a known risk. The vulnerability is local, requiring the attacker to have logon privileges on the infrastructure hosting WebCenter Content, yet once achieved, the attacker can access all content. Because the flaw can broaden the attack surface to other Oracle products, the scope can change, amplifying potential damage.
OpenCVE Enrichment