Impact
A flaw in Oracle WebCenter Content allows an unauthenticated attacker with network access over HTTP to coerce a legitimate user into executing actions that give the attacker unrestricted modification and deletion rights over critical data. The vulnerability enables the attacker to read, alter, or erase content managed by the Content Server, effectively compromising the confidentiality and integrity of all data exposed through that instance.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity, primarily affecting confidentiality and integrity. The EPSS score of less than 1% suggests that exploitation is considered unlikely at this time, yet the vulnerability remains network-unauthenticated HTTP access along with minimal user interaction to trigger. Because the attack can scale from a single user to full control over all managed data and the vulnerability is not currently listed in CISA’s KEV catalog, the risk to exposed deployments remains significant as attackers may perform destructive or illicit actions if they can persuade a user to participate.
OpenCVE Enrichment