Impact
The Oracle WebCenter Portal runtime component contains a flaw that allows an attacker with only low privileges but network access over HTTP to gain full control of the application. The vulnerability is classified as a remote code execution with an impact on confidentiality, integrity, and availability, as reflected by the CVSS score of 9.9. It is a classic case of improper access control (CWE‑284) that can lead to a complete takeover of the portal and potentially other applications in the same environment because the scope is marked as changed.
Affected Systems
Affected products are Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0. These are part of Oracle Fusion Middleware and are used in many enterprise web portals.
Risk and Exploitability
The EPSS score is below 1 %, indicating that exploit traffic is currently rare but the vulnerability remains theoretically easy to exploit from any machine that can reach the portal over HTTP. Because the required privileges are low and the attack vector is network‑based, the threat to organizations that expose the portal to the internet or to untrusted internal networks is significant. The flaw is not yet listed in the CISA KEV catalog, but the high CVSS, scope change, and remote nature warrant immediate attention.
OpenCVE Enrichment