Impact
Oracle WebCenter Portal contains a flaw in its Runtime Tools component that permits an attacker with network access via HTTP to compromise the portal. The vulnerability allows the attacker to execute actions with the same privileges as the portal service, leading to complete control over the application and its data. The potential impact includes full compromise of confidentiality, integrity, and availability, resulting in a total portal takeover.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Both versions expose a public HTTP interface that is reachable from the network, permitting connections by unauthenticated users.
Risk and Exploitability
The CVSS 3.1 score of 9.8 indicates critical severity, and the EPSS < 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, yet its unauthenticated HTTP path is remote and requires no special privileges or local access. An attacker simply needs to craft a request to a vulnerable endpoint, enabling full control of the portal with no authentication.
OpenCVE Enrichment