Impact
This vulnerability resides in the Core component of Oracle WebCenter Content: Imaging and permits an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation requires a human interaction from a person other than the attacker; once achieved, the attacker can take over the entire WebCenter Content: Imaging environment. The CVSS 3.1 base score of 7.5 reflects that confidentiality, integrity and availability would all be substantially affected.
Affected Systems
Affected products are Oracle WebCenter Content: Imaging version 12.2.1.4.0 and 14.1.2.0.0. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score indicates high severity, but the EPSS probability is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a relatively low likelihood of widespread exploitation at this time. The likely attack vector is via a public‑facing HTTP interface, where an attacker can initiate a request to the vulnerable Core component. Successful attacks would occur only when a legitimate user interacts with the system on behalf of the attacker, after which the attacker could gain full control of the application.
OpenCVE Enrichment