Impact
This vulnerability in Oracle WebCenter Content’s Web Content Management component allows an attacker with low privileges and network access via HTTP to compromise the application. The flaw is exploitable through an unauthenticated or low‑privilege path and requires the cooperation of a user not controlled by the attacker. The weakness is rooted in improper input validation (CWE‑20), lack of transport‑layer security (CWE‑295), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and misconfigured file‑path handling (CWE‑640). If successfully exploited, the attacker can take over the entire WebCenter Content instance, gaining complete control over its data and services, which results in substantial confidentiality, integrity, and availability damage.
Affected Systems
The affected products are Oracle WebCenter Content, version 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. No additional vendor or product variants are listed. Organisations using either of these releases must investigate whether they host the vulnerable component.
Risk and Exploitability
The CVSS score of 8.0 reflects significant risk while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is over the network via HTTP, and although it requires human interaction, a single compromised user can enable a full takeover, making it a high‑risk threat for businesses that expose their WebCenter Content interfaces to the internet.
OpenCVE Enrichment