Impact
The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and allows an unauthenticated network attacker to connect via the T3 or IIOP protocols. By exploiting the missing authentication flaw (CWE-306), the attacker can fully compromise the application, gaining control that threatens confidentiality, integrity, and availability. This flaw is manifested as an authentication bypass that grants complete takeover of the affected instance.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability impacts systems running these releases of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 classifies this issue as critical, with no privileges required and no user interaction needed. The EPSS score of less than 1% indicates that widespread exploitation is currently limited, yet the vulnerability is not listed in CISA KEV. An attacker only needs basic network access to the exposed T3 or IIOP endpoints to trigger the exploit, making it highly addressable with direct reconnaissance.
OpenCVE Enrichment