Impact
An Oracle WebCenter Content: Imaging flaw in the Core component lets an attacker with low privileges and network access via HTTP exploit improper access control (CWE‑284). The vulnerability requires a separate, human‑initiated interaction but otherwise is easily exploitable. When successful, the attacker can create, delete, or modify critical data and gain unauthorized access to all data readable by the Imaging application, potentially affecting associated products through a scope change. The exploitation would compromise confidentiality and integrity of sensitive information.
Affected Systems
Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected; the flaw impacts the core component of the product, and exploitation may propagate to other products that interact with Imaging.
Risk and Exploitability
The issue carries a CVSS 3.1 base score of 8.7, indicating high confidentiality and integrity impact. The EPSS score is below 1 %, suggesting that, so far, observed exploitation is rare. The flaw is not in the CISA KEV catalog, but the ability to be triggered over HTTP by a low‑privileged user and the requirement for a second party interaction still make it an appealing target for attackers. With a limited exploitation window yet significant damage potential, organizations should treat this as a high‑risk vulnerability.
OpenCVE Enrichment