Impact
Oracle WebCenter Content contains a set of weaknesses that allow an unauthenticated attacker with network access via HTTP to compromise the Content Server. The flaw combines improper input validation (CWE‑20), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and cross‑site scripting (CWE‑79). An attacker must obtain the cooperation of a separate user to confirm a prompt or provide input; after this interaction, the attacker can execute arbitrary code and take full control of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected, and the exposed component is the Content Server.
Risk and Exploitability
The CVSS base score is 8.8, indicating high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently very low, yet the vulnerability remains exploitable. It is not listed in the CISA KEV catalog, which further implies no known widespread exploitation. However, the requirement of user interaction introduces a social engineering component that could lower the overall barrier of attack. Organizations should treat this as a high‑priority risk even with the low EPSS.
OpenCVE Enrichment