Impact
The vulnerability resides in the client bundle of Oracle WebCenter Enterprise Capture and represents an access control flaw (CWE-284) that permits a low‑privileged user with network access over the T3 or IIOP protocols to compromise the application. Successful exploitation can result in full takeover, leading to disclosure, modification, or denial of confidentiality, integrity and availability.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware. Since the vulnerability can change scope, other Oracle Fusion Middleware components may also be impacted even if they are not listed directly.
Risk and Exploitability
The CVSS base score of 9.9 highlights critical severity. With an EPSS score below 1%, the likelihood of immediate exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack can be carried out automatically over the network using T3 or IIOP, requiring only low privileges and no user interaction.
OpenCVE Enrichment