Impact
The vulnerability in Oracle WebCenter Content: Imaging allows an attacker with low privileges but network access via HTTP to bypass access controls and gain unauthorized access to data. The attacker can read sensitive information or update, insert, or delete data that the system normally protects. The impact is significant confidentiality and integrity compromise for content stored in the product, as reflected by the CVSS score of 7.1, which values high confidentiality impact and low integrity impact.
Affected Systems
Affected products are Oracle WebCenter Content: Imaging, versions 12.2.1.4.0 and 14.1.2.0.0. The issue exists in the Core component of the Fusion Middleware stack and requires an Oracle WebCenter environment to be exploited.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high severity. The EPSS score of <1% indicates that actual exploitation is unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via network access through HTTP to the WebCenter Content: Imaging service, with a low‑privileged attacker able to gain unauthorized access to data.
OpenCVE Enrichment