Impact
An access‑control flaw in Oracle WebCenter Portal’s Runtime Tools permits an attacker who already has limited access over HTTP to elevate privileges and ultimately gain full control of the portal. The vulnerability does not require authentication or high privileges, and its exploitation would compromise the confidentiality, integrity and availability of the entire portal environment, enabling attacker‑controlled changes, data exfiltration or service disruption.
Affected Systems
Oracle Corporation’s WebCenter Portal component within Oracle Fusion Middleware, specifically the Runtime Tools. Supported affected releases include 12.2.1.4.0 and 14.1.2.0.0. Any installation of these versions exposed to HTTP traffic from untrusted networks is vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high severity risk that attackers can achieve compromise from a network accessible point with low attack complexity and low privileges. The EPSS score of less than 1 % suggests the current likelihood of exploitation is low, but the flaw remains critical for environments that allow public or loosely secured portal access. The vulnerability is not listed in the CISA KEV catalog, yet its potential impact warrants immediate attention. An attacker can exploit the flaw remotely over HTTP without needing prior authentication, making the risk significant for exposed portals.
OpenCVE Enrichment