Impact
A vulnerability in Oracle WebCenter Content allows an attacker that already possesses high‑privilege credentials to exploit a flaw over HTTP and take full control of the system, compromising confidentiality, integrity, and availability. The issue is a CWE‑284 Improper Access Control vulnerability that is deemed easily exploitable based on the vendor’s description and the CVSS vector indicates a normally accessible HTTP interface with low attack complexity. Successful exploitation means the attacker can effectively assume control of the WebCenter Content instance.
Affected Systems
Oracle WebCenter Content is affected for the versions listed as 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware’s Web Content Management component. Administrators should verify whether their installations match these exact versions using the provided CPE strings or their own product version identifiers.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 reflects a moderate‑to‑high risk level with full confidentiality, integrity and availability impacts. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at the time of the analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over a network‑exposed HTTP interface; however, the attacker must possess high privileged credentials or a compromised computer within the network to reach the vulnerable service. No known public exploits for this specific CVSS score have been reported yet, but the described ease of exploitation warrants precautionary action.
OpenCVE Enrichment