Impact
Oracle WebCenter Content product of Oracle Fusion Middleware, component Content Server, suffers from an easily exploitable vulnerability (CWE-284). The flaw allows a low‑privileged attacker with network access to the application via HTTP to compromise the installation. Successful exploitation requires human interaction from a user other than the attacker but can result in the attacker gaining unauthorized access to critical data, as well as the ability to insert, update or delete data within the content repository. The CVSS 3.1 base score is 7.6, reflecting high confidentiality impact and low integrity impact.
Affected Systems
Oracle Corporation’s Oracle WebCenter Content, versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability appears in the Content Server component of the Fusion Middleware stack and can affect any deployment of these software releases.
Risk and Exploitability
The CVSS score of 7.6 denotes a high risk for confidentiality loss, while the EPSS for this vulnerability is under 1% indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely over the network via HTTP, with the attacker requiring only a low level of privilege and the cooperation of a user to trigger the payload. Because the flaw can extend its impact to additional products within the same environment, the potential damage may be broader than the initial scope.
OpenCVE Enrichment