Impact
A flaw in Oracle WebCenter Content’s Content Server component allows an unauthenticated attacker with network access over HTTP to trigger actions that create, modify, or delete content. The primary impact is the compromise of confidentiality and integrity for all data stored in the system, as the attacker can gain unauthorized access to critical data or full control over accessible content. Based on the description, it is inferred that the attacker must obtain a third‑party user’s input or action to exploit this flaw, implying a social‑engineering requirement.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. Any installation of these releases without the vendor patch is at risk, and due to the scope change mentioned, additional Oracle Fusion Middleware products that rely on the WebCenter Content server may also be affected.
Risk and Exploitability
The CVSS v3.1 base score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The required human interaction is inferred from the wording that an attacker needs a third party, so the likely attack vector involves an unauthenticated HTTP endpoint combined with social‑engineering or phishing to prompt the user to initiate the exploit.
OpenCVE Enrichment