Impact
The vulnerability enables an attacker who already has high network privileges to take full control of Oracle WebCenter Content Imaging by exploiting a flaw that becomes evident when the system communicates via the T3 or IIOP protocols. The weakness is classified as CWE-284, an improper privilege assignment, and it can lead to a complete loss of confidentiality, integrity, and availability of the application. The affected component is the Core part of the WebCenter Content Imaging product, with the CVSS 3.1 base score 7.2 indicating moderate to high severity.
Affected Systems
Affected are Oracle Corporation WebCenter Content Imaging, versions 12.2.1.4.0 and 14.1.2.0.0. These versions are supported by the latest CPU July 2026 advisory.
Risk and Exploitability
The flaw has a CVSS base score of 7.2, the EPSS score is less than 1% indicating a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network-based exploitation through the T3 and IIOP protocols, requiring the attacker to already possess high privileged credentials in order to compromise the application.
OpenCVE Enrichment