Impact
The vulnerability in Oracle WebCenter Content permits an unauthenticated attacker who can reach the application over HTTP to compromise the system without a valid account; although difficult and requiring interaction from a user other than the attacker, a successful exploit would grant the attacker full control over the Content Server, exposing confidential data, enabling unauthorized changes, and disrupting availability. This flaw involves weaknesses in input validation, improper authentication, and misconfiguration that facilitate remote code execution.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These deployments are part of Oracle Fusion Middleware and are commonly used in enterprise content management environments.
Risk and Exploitability
The CVSS base score of 8.3 indicates high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attacks require network access to the HTTP interface and a susceptible user to interact, likely via social engineering. Once compromised, the attacker can fully control the Content Server and potentially impact integrated products due to a scope change.
OpenCVE Enrichment