Impact
The vulnerability allows a low‑privileged attacker with HTTP network access to compromise Oracle WebCenter Content: Imaging. Successful exploitation gives the attacker unauthorized read access to critical data, and the ability to insert, update or delete accessible data. The CVSS 3.1 Base Score of 8.5 reflects high confidentiality impact and moderate integrity impact, and the scope change indicates that additional products may also be affected when the attack succeeds.
Affected Systems
Oracle WebCenter Content: Imaging, Fusion Middleware component Core, versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Only these two releases are listed as vulnerable in the advisory.
Risk and Exploitability
The vulnerability is considered high severity but the EPSS score is below 1%, indicating a low likelihood of exploitation at present. The attack vector is network-based via HTTP, and the vulnerability requires a low privileged attacker. It is not listed in CISA’s KEV catalog, and the scope change raises the possibility that related applications might be affected once the vulnerability is leveraged.
OpenCVE Enrichment