Impact
A vulnerability in Oracle WebCenter Portal allows a low‑privileged attacker with HTTP network access to compromise the portal. An attacker can exploit the Runtime Tools component using crafted HTTP requests, resulting in full takeover of the portal and loss of confidentiality, integrity, and availability. The flaw is an authentication weakness (CWE‑287) and carries a CVSS 3.1 base score of 9.9, indicating a critical risk for remote adversaries.
Affected Systems
Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. The scope change may also affect additional components of Oracle Fusion Middleware, so related services should be verified for impact.
Risk and Exploitability
The EPSS score of < 1% indicates that exploitation is not yet common, but the high CVSS score and the low privilege required mean that an attacker could launch an attack without special permissions. The vulnerability is not listed in the CISA KEV catalog, so no public exploit code is confirmed. Based on the description, it is inferred that an attacker might send crafted HTTP requests to the exposed Runtime Tools interface, enabling full access to the portal. Because the attack vector is remote network access, protecting the network perimeter and monitoring HTTP traffic are critical mitigation measures.
OpenCVE Enrichment