Impact
The vulnerability resides in Oracle WebCenter Content and allows a low‑privileged attacker with network access via HTTP to bypass access controls and obtain unauthorized access to sensitive data or all accessible content. Successful exploitation can also cause a partial denial of service, degrading availability. The CVSS 3.1 Base Score of 7.1 reflects a high confidentiality impact and a low availability impact.
Affected Systems
Affected products are Oracle WebCenter Content, part of Oracle Fusion Middleware under the Web Content Management component. The versions impacted are 12.2.1.4.0 and 14.1.2.0.0. No other product versions are listed as affected.
Risk and Exploitability
The CVSS score indicates a high severity risk, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires only low‑privilege network access to the WebCenter Content HTTP interfaces, making the attack vector network‑based and relatively easy to launch.
OpenCVE Enrichment