Impact
The vulnerability enables an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. The vulnerability arises from multiple weaknesses including insufficient input validation (CWE‑20), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and cross‑site scripting (CWE‑79). Successful exploitation requires user interaction from a third party and can lead to full takeover of the content server, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. These versions of the Content Server component are affected, and any installations using these product releases expose the system to risk.
Risk and Exploitability
The CVSS base score of 8.8 reflects high severity. The EPSS score is less than 1%, indicating low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP with no prior authentication and requires user interaction, meaning an attacker must persuade a legitimate user to complete an action that triggers the exploit.
OpenCVE Enrichment