Impact
An unauthenticated HTTP vector allows an attacker with network access to potentially access confidential data, insert or delete data, and cause a partial denial of service in Oracle WebCenter Content. The weakness appears to be related to improper authentication and authorization, allowing an unauthenticated user to perform privileged actions.
Affected Systems
Oracle WebCenter Content of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0, is affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.6 indicates high confidentiality impact and moderate integrity and availability impact. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires human interaction from an entity other than the attacker and relies on the ability to reach the web application over HTTP.
OpenCVE Enrichment