Impact
The vulnerability stems from insufficient input validation (CWE‑20) and insecure handling of cross‑site request forgery (CWE‑352), open redirects (CWE‑601), and cross‑site scripting (CWE‑79) within Oracle WebCenter Content’s Content Server component. An attacker who is able to send unauthenticated HTTP requests to the server can ultimately trigger a takeover, but the successful exploitation requires human interaction to complete the attack sequence. The impact is a full compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
Oracle WebCenter Content products, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 score of 8.8 indicates a high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is invoked via network‑based HTTP requests to the vulnerable component, and the exploit path requires the presence of an interactive human to complete the takeover after initial access.
OpenCVE Enrichment