Impact
A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access via HTTP to compromise the system and potentially take full control. The flaw can lead to a complete takeover, damaging confidentiality, integrity, and availability, as indicated by a CVSS 3.1 score of 8.8. Successful exploitation requires human interaction with a user other than the attacker, suggesting a social‑engineering component in the attack chain. The impact is system‑wide, affecting all users and data stored in the compromised instance.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions run within Oracle Fusion Middleware and are deployed in enterprise environments that expose the Content Server over HTTP.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score is less than 1 %, indicating a low but non‑zero probability of exploitation at any given moment. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread attacks are known. Exploitation can occur via HTTP traffic to the Content Server, and the flaw can be exploited by an unauthenticated attacker who succeeds in tricking a legitimate user into assisting with the attack.
OpenCVE Enrichment