Impact
A flaw in the Oracle WebCenter Enterprise Capture client bundle allows an attacker with low privileges and network reachability via the T3 or IIOP protocols to gain unauthorized remote execution on the application. The weakness stems from insufficient access control, enabling attackers to bypass authentication and take control of the system, thereby exposing confidentiality, integrity, and availability of the application.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical level of severity. The EPSS score of less than 1 % suggests that exploitation is uncommon at present, and the vulnerability is not listed in CISA’s KEV catalog. However, the potential for full takeover makes it a high‑risk target for adversaries that can reach the T3 and IIOP services over the network.
OpenCVE Enrichment