Impact
The CVE identifies a vulnerability in the Core component of Oracle WebCenter Content: Imaging. The weakness is an access control flaw (CWE-284), allowing a low‑privileged attacker who can reach the service over the network via the T3 or IIOP protocols to exploit the flaw, resulting in a full compromise of the application. This compromise jeopardizes the confidentiality, integrity, and availability of the system.
Affected Systems
Affected are Oracle Corporation's WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0, as published in the Oracle Fusion Middleware portfolio. No other product versions are currently reported as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score of less than 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network access over T3 or IIOP and no special credentials; a low‑privileged attacker can send crafted requests to trigger the compromise once connectivity is established.
OpenCVE Enrichment