Impact
Oracle WebCenter Content is vulnerable to a remote authentication bypass that can be exploited over HTTP. The flaw allows an unauthenticated attacker to access, modify, or delete protected content and to trigger a partial denial of service. The weakness is rooted in improper access control (CWE‑284) and insecure redirect handling (CWE‑601), with a CVSS 3.1 base score of 7.6 indicating significant confidentiality, integrity, and availability impacts.
Affected Systems
Records show that Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and are commonly deployed by enterprises for managing knowledge and documents.
Risk and Exploitability
The opportunistic exploit requires only network access to the HTTP interface, and an attacker can cause the vulnerability to take effect by tricking a user into interacting with a crafted request (UI required). Although the EPSS score is listed as < 1 %, the absence of any current exploitation reports does not negate the risk, and the vulnerability is not in CISA’s KEV list. Clients should therefore treat it as a serious security issue and apply the vendor patch promptly.
OpenCVE Enrichment