Impact
An easily exploitable vulnerability allows a low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. The attack leads to takeover of the application and provides full confidentiality, integrity, and availability impact, as indicated by a CVSS 3.1 Base Score of 9.9 and the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS score of 9.9 marks this as critical, while the EPSS score of less than 1% indicates a very low probability of exploitation at present and the vulnerability is not listed in the CISA KEV catalog. The attack vector is over the network via HTTP, requiring only low privileges. Based on the description, it is inferred that the scope change may affect other Oracle Fusion Middleware components, potentially impacting additional products. Successful exploitation would result in a complete takeover of the application.
OpenCVE Enrichment