Impact
The flaw in Oracle WebCenter Content allows an unauthenticated attacker to send crafted HTTP requests that can gain full control of the application. The weakness is rooted in cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and cross‑site scripting (CWE‑79) vulnerabilities that together enable the attack. Based on the description, it is inferred that successful exploitation requires human interaction from a person other than the attacker, which limits the window for a successful compromise.
Affected Systems
Oracle WebCenter Content, versions 12.2.1.4.0 and 14.1.2.0.0, is part of Oracle Fusion Middleware. These versions run on both on‑premises and cloud configurations.
Risk and Exploitability
The CVSS 3.1 rating of 8.8 indicates high severity, while an EPSS score below 1% suggests a low likelihood of exploitation in the wild at this time. The vulnerability is not registered in CISA’s KEV catalog. Attackers need only network access over HTTP, but successful exploitation requires human interaction from a user other than the attacker, which further limits the attack window. Given the remote nature and the potential for full system takeover, the overall risk remains significant if the vulnerability is not mitigated promptly.
OpenCVE Enrichment