Impact
Vulnerability in the Oracle WebCenter Content product allows an unauthenticated attacker with network access via HTTP to compromise the Content Server. Based on the description, it is inferred that the flaw results in an authentication bypass, although the precise mechanism is not detailed. The impact includes complete compromise of confidentiality, integrity, and availability, as the attacker can potentially execute arbitrary commands or read/write any data. The weakness corresponds to CWE‑306, reflecting missing or inadequate authentication.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware are affected. These products are deployed in many enterprise environments, providing content and collaboration services.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high ratio of confidentiality, integrity, and availability impact. The EPSS score of less than 1 % suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The probable attack vector is a network‑based HTTP request that does not require prior authentication and can be executed by any external party with internet exposure.
OpenCVE Enrichment