Impact
The vulnerability resides in the Content Server component of Oracle WebCenter Content and permits an attacker with network access over HTTP to gain unauthorized control of the system. Because no authentication is required and the exploitation pathway is simple, an unauthenticated attacker can seize the entire platform, resulting in loss of confidentiality, integrity and availability. The attack also demands a human interaction from an entity other than the attacker, implying a social‑engineering component to the successful exploitation.
Affected Systems
Affected product: Oracle WebCenter Content, part of Oracle Fusion Middleware. Versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. The flaw lies within the Content Server module.
Risk and Exploitability
The CVSS base score of 8.8 underscores a high‑severity risk, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, the combination of remote accessibility via HTTP and the ability to fully takeover the platform makes it a pressing issue. Attackers may exploit this once the service is exposed over the network, so preventing external HTTP access is critical.
OpenCVE Enrichment