Impact
Low‑privileged attackers with network access over HTTP can exploit this Oracle WebCenter Content flaw to achieve a full takeover of the application, compromising confidentiality, integrity, and availability. The vulnerability requires a secondary user, other than the attacker, to perform an action that triggers the exploit. The weakness is a Cross‑Site Request Forgery (CWE‑352), allowing an attacker to forge requests on behalf of the victim and execute privileged operations leading to full control of the content server.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected by this flaw.
Risk and Exploitability
The flaw is rated with a CVSS 3.1 base score of 8.0, indicating a high severity with significant confidentiality, integrity, and availability impact. The EPSS score is below 1 %, suggesting a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can occur over the network via HTTP, and it relies on user interaction from a non‑attacker. An attacker can prepare a malicious request and convince a legitimate user to trigger it, leading to full control of the WebCenter Content instance. While no public exploits are known, the high impact warrants prompt attention.
OpenCVE Enrichment