Impact
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 suffer from a combination of improper input validation, cross‑site request forgery, open redirect, and reflected cross‑site scripting weaknesses. This flaw allows an unauthenticated attacker with network access via HTTP to bypass authentication controls and ultimately gain full control of the Content Server, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Affected systems are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, the primary applications within Oracle Fusion Middleware that provide content management services.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw is reachable over HTTP and requires user interaction (UI:R), a determined attacker could coerce or trick a user into initiating the exploit, making the risk relevant for environments exposing WebCenter Content to untrusted networks.
OpenCVE Enrichment