Impact
The CVE details an unauthenticated web access vulnerability in Oracle WebCenter Content that allows an attacker with normal HTTP network access to take over the application. The flaw is due to insufficient privilege verification (CWE‑306), which lets remote attackers act as a privileged user without authenticating. Successful exploitation results in complete compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of the Oracle Fusion Middleware suite and are commonly deployed in enterprise content management environments. Based on the description, it is inferred that attacks may significantly impact additional products because the vulnerability can change scope within the same environment.
Risk and Exploitability
The CVSS score of 10.0 marks this vulnerability as critical, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is easily exploitable, requiring only unauthenticated HTTP requests to the affected instance. Because it is not listed in the CISA KEV catalog, the risk assessment relies on the severity and exploitability metrics. Attackers can achieve full takeover of the WebCenter instance, making aggressive mitigation imperative.
OpenCVE Enrichment