Impact
Oracle WebCenter Portal contains a low‑privilege HTTP vulnerability that permits any user with network connectivity to send crafted requests which can create, delete, or modify critical portal data and grant full read access to all portal content. The flaw exploits improper authorization (CWE‑284) and, as the CVE describes, may affect other products with a scope change, compounding the damage beyond the portal itself.
Affected Systems
The affected products are Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware. No other product versions are currently listed as impacted.
Risk and Exploitability
The CVSS base score of 9.6 signals a severe confidentiality and integrity risk. The EPSS score of < 1 % indicates that widespread exploitation is currently unlikely, yet the vulnerability remains actionable. Because the attack can be performed over HTTP with only low privilege, an adversary can exploit it from any network‑connected host. The flaw is not yet cataloged in the CISA KEV, but its ability to alter and read portal data makes it a critical risk for organizations relying on WebCenter Portal.
OpenCVE Enrichment