Impact
The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and enables a low‑privileged attacker with network access through T3 or IIOP to compromise the application. Attackers can achieve full takeover of the product, leading to complete loss of confidentiality, integrity, and availability. The impact can extend beyond the WebCenter product, potentially affecting other Oracle Fusion Middleware components.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the fusion middleware of these releases, and because of the scope change described, many other Oracle Fusion Middleware applications may also be at risk if they rely on WebCenter components.
Risk and Exploitability
The CVSS v3.1 score of 9.9 marks it as Critical, with network-based attacks requiring only low privileges and no user interaction. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, yet the vulnerability is not listed in CISA’s KEV catalogue. The easy‑to‑exploit nature and its potential to compromise multiple products make it a high priority for remediation, even if active exploit activity has not yet been observed.
OpenCVE Enrichment