Impact
A low‑privileged attacker who can reach Oracle WebCenter Content over HTTP can exploit a flaw identified as CWE‑284 (Improper Authorization). The weakness allows the attacker to create, delete, or modify critical data, resulting in unauthorized access to all data held by the system. The impact is significant on confidentiality and integrity, and the scope change means related products may also be affected.
Affected Systems
Oracle WebCenter Content, a product of Oracle Corporation, is affected. The vulnerable releases are version 12.2.1.4.0 and 14.1.2.0.0; any deployments of these releases may be compromised during exploitation.
Risk and Exploitability
The CVSS score of 8.7 categorises this as high severity, while the EPSS score of < 1% indicates that, at present, the likelihood of exploitation is low. Being listed in no KEV catalogue further mitigates immediate urgency from a known exploited standpoint. However, the vulnerability’s scope change allows a successful attack to potentially affect adjacent products in the same environment. The attack vector is remote over HTTP and requires low‑privilege access and user interaction to activate, suggesting that it may be leveraged through social engineering practices or malicious web content.
OpenCVE Enrichment