Impact
A low‑privileged attacker who can reach Oracle WebCenter Content over HTTP can exploit a set of vulnerabilities—including cross‑site request forgery, open redirect, path traversal, and cross‑site scripting—to gain full control of the application. Successful exploitation requires that a separate user act on the attacker’s behalf, committing a user interaction to complete the attack. If the exploit succeeds, the attacker can read, modify, or delete content, tamper with configuration, and disrupt availability, thereby compromising confidentiality, integrity, and availability of the entire content management system.
Affected Systems
Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware that provide enterprise web content management, are affected.
Risk and Exploitability
The CVSS base score of 8.0 indicates high severity. An EPSS score of less than 1 % suggests a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is an HTTP request from a low‑privileged user; the attacker must persuade or prompt another user to carry out an action that completes the exploitation process. Given the high potential impact, affected deployments face a significant risk.
OpenCVE Enrichment