Impact
A flaw in the Runtime Tools component of Oracle WebCenter Portal allows an attacker with low privileges who can reach the system over HTTP to compromise the portal. The vulnerability is easily exploitable and can give the attacker full control of the portal, potentially affecting other integrated applications. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates a scope change, leading to confidentiality, integrity, and availability impacts beyond the initial target.
Affected Systems
The affected products are Oracle WebCenter Portal from Oracle Corporation, specifically version 12.2.1.4.0 and 14.1.2.0.0. No other versions are listed as vulnerable in the current advisory.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical severity. The EPSS score falls below 1% and the vulnerability is not listed in CISA’s KEV catalog, yet the high severity score and scope shift suggest it may be of interest to attackers. Exploitation requires only network access to the portal’s HTTP interface and does not require authentication or elevated privileges. A successful exploit can be achieved via a simple HTTP request, allowing the attacker full control of the portal.
OpenCVE Enrichment