Impact
Oracle WebCenter Enterprise Capture is vulnerable to a highly exploitable flaw that allows a low privileged attacker with network access via HTTP to take full control of the system. An attacker can compromise the confidentiality, integrity, and availability of the product, resulting in a complete takeover. The weakness resides in the Client Bundle component and can lead to execution of arbitrary code with local privileges on the host.
Affected Systems
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0 issue is specific to these builds, but compromise of the capture component may also impact other Oracle Fusion Middleware products due to scope changes noted in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 reflects a high impact with easy exploitation (low authentication required). The attack vector is likely remote over HTTP, and the estimated EPSS score of less than 1% indicates a low but nonzero probability of exploitation. The CVSS vector indicates a scope change (S:C), which may affect other components of the application. The vulnerability is not yet listed in CISA's KEV catalog, but the severity and potential for takeover make it a critical risk for any impacted environment.
OpenCVE Enrichment