Impact
This vulnerability grants an unauthenticated attacker, with network access via HTTP, the ability to create, delete, or modify data within Oracle WebCenter Content. The attacker could also gain complete unauthorized access to all data the application can reach, leading to significant confidentiality and integrity compromises. The weakness allows the attacker to bypass authentication controls, causing a direct breach of data protection safeguards.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected, as noted by the vendor alert.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 highlights the high severity of this flaw, and the ease of exploitation is amplified by the lack of required privileges. The EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely, yet the flaw is still highly critical. When combined with active network exposure via HTTP, an attacker can immediately exploit the weakness to compromise confidential data. The vulnerability is not listed as a known exploited vulnerability in CISA KEV, but the potential impact remains substantial.
OpenCVE Enrichment