Impact
The WebCenter Content: Imaging product is vulnerable to an easily exploitable flaw that permits a low‑privileged attacker who can reach the system over HTTP to take over the application. The attacker can gain full control of the system, including the ability to alter or delete data and to fully compromise the service, thereby destroying confidentiality, integrity and availability.
Affected Systems
Oracle WebCenter Content: Imaging component of Oracle Fusion Middleware. Affected releases include version 12.2.1.4.0 and version 14.1.2.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high‑severity vulnerability. The EPSS score is less than 1%, suggesting a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP with low privileges; an attacker does not need elevated rights and only needs network connectivity to the application’s HTTP interface.
OpenCVE Enrichment