Impact
An unauthenticated attacker with network access can exploit a vulnerability in Oracle WebCenter Content: Imaging via the T3 and IIOP protocols to take over the application. The flaw, affecting the Core component, allows a remote attacker to execute code with the privileges of the application process, resulting in total compromise of confidentiality, integrity, and availability. The CVSS 3.1 score of 9.8 indicates a critical severity and reflects the full loss of control over the affected system.
Affected Systems
Oracle Corporation’s WebCenter Content: Imaging product is affected, specifically versions 12.2.1.4.0 and 14.1.2.0.0. These releases remain widely deployed in enterprise environments that rely on imaging capabilities within the Fusion Middleware stack.
Risk and Exploitability
The CVSS score of 9.8 assigns this vulnerability a critical rating. The EPSS score of less than 1% indicates that, despite its high severity, the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is network‑based (AV:N), requires no prior authentication or user interaction, and can be performed by an attacker who can reach the T3 or IIOP interfaces over the network, making it potentially exploitable from publicly accessible services.
OpenCVE Enrichment