Impact
An unauthenticated, remote attacker can exercise control over Oracle WebCenter Content through a vulnerable HTTPS endpoint, allowing full compromise of the application. The flaw permits the attacker to bypass authentication checks, leading to significant loss of confidentiality, integrity, and availability. The CVSS score of 8.1 reflects the severe impact on all three core security properties.
Affected Systems
The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware’s Content Server. Any deployment of these versions is vulnerable unless patched or otherwise protected.
Risk and Exploitability
The attack vector is network‑based via HTTPS. Although the EPSS probability is below 1% and the flaw is not yet listed in CISA’s KEV catalog, the high CVSS score and the possibility of full system compromise make this a high‑risk issue. An attacker would need network reach to the WebCenter Content instance but no credentials and can rely on the exposed HTTPS interface to achieve takeover.
OpenCVE Enrichment