Impact
The vulnerability resides in the Core component of Oracle WebCenter Content: Imaging. It is an improper access control flaw (CWE‑284) that enables a low‑privileged attacker who can reach the application over HTTP to compromise the instance. Successful exploitation can lead to a complete takeover of the WebCenter Content: Imaging application, resulting in loss of confidentiality, integrity, and availability of data and services that the application manages.
Affected Systems
Affected deployments are Oracle WebCenter Content: Imaging version 12.2.1.4.0 and 14.1.2.0.0, the two releases listed by Oracle in the CPU update. No other versions are flagged as vulnerable in the public advisory.
Risk and Exploitability
The base CVSS 3.1 score of 8.8 indicates high severity, and the vector shows network access with low authentication and no user interaction. The EPSS score is less than 1%, and the vulnerability is not yet listed in the CISA KEV catalog. This indicates that while the technical risk is high, active exploitation in the wild is currently rare, yet any environment exposing the application over the network remains at significant risk.
OpenCVE Enrichment