Impact
The flaw, an instance of CWE‑284 Improper Access Control, resides in the Core component of Oracle WebCenter Content: Imaging and permits an attacker with physical communication segment access to compromise the system without authentication. Successful exploitation can lead to full takeover of WebCenter Content: Imaging, thereby affecting confidentiality, integrity, and availability of data and services. The vulnerability is located in WebCenter Content: Imaging, but attacks may also affect additional products due to a scope change.
Affected Systems
Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Users of these versions should verify installation and patch status.
Risk and Exploitability
The CVSS v3.1 base score of 8.3 indicates high severity, while the EPSS score of less than 1% shows a low exploitation probability as of the current data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an internal, unauthenticated connection to the physical network segment; the attacker does not need elevated privileges outside the communication channel. If exploited, an attacker can fully control the affected instance and potentially reach other applications due to the scope change.
OpenCVE Enrichment