Impact
A low‑privileged attacker with network connectivity can abuse an HTTP endpoint in Oracle WebCenter Content: Imaging to compromise the application. Successful exploitation permits the attacker to create, delete, or alter any data that the application can access, and may grant full read access to all such data. The vulnerability is a weakness in the core component, enabling the attacker to bypass normal security controls. The impact is classified as a high‑severity confidentiality and integrity breach per the CVSS 3.1 score of 8.7.
Affected Systems
Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the core component of the product and may also affect other Oracle Fusion Middleware components due to a scope change.
Risk and Exploitability
The CVSS base score indicates a high severity. The EPSS score is reported as less than 1%, suggesting that the likelihood of exploitation at this time is very low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack requires only HTTP access and low privileges, but also human interaction from a non‑attacker to complete the compromise, which increases the friction for exploitation. The vulnerability can impact additional products because of a scope change, potentially expanding the damage footprint.
OpenCVE Enrichment