Impact
A vulnerability in the Oracle WebCenter Enterprise Capture client bundle allows an attacker who can reach the system via the T3 or IIOP protocols to gain full control of the application, compromising confidentiality, integrity, and availability. The issue is classified as a Remote Code Execution scenario with the potential to affect other dependent products because the exploit can change the overall scope of compromise. The CVE demonstrates that even a low‑privileged attacker can execute arbitrary code if this flaw is present, emphasizing the severity of the attack.
Affected Systems
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0. These are the only affected releases according to the CNA data, and the product belongs to the Oracle Fusion Middleware suite.
Risk and Exploitability
With a CVSS v3.1 score of 9.9, the vulnerability represents a critical level of risk. The EPSS score is below 1%, indicating that the probability of exploitation in the wild is low, and the vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access via T3 or IIOP, requiring only low privileges, which allows an attacker to bypass authentication controls and execute arbitrary code.
OpenCVE Enrichment