Impact
A low-privileged attacker who can reach the service over HTTP can exploit an issue in Oracle WebCenter Content that relates to CWE-20 (Improper Input Validation), CWE-352 (Cross‑Site Request Forgery), CWE-601 (Open Redirect), CWE-640 (Improper Authentication), and CWE-79 (Cross‑Site Scripting). The vulnerability requires cooperation from another user, indicating a social engineering or phishing vector. Successful exploitation results in full control of the application, giving the attacker unrestricted access to all data and administrative functions, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.0 rates the vulnerability as high severity. The weakness corresponds to CWE-20, CWE-352, CWE-601, CWE-640, and CWE-79, enabling improper input validation, cross‑site request forgery, open redirect, improper authentication, and cross‑site scripting that facilitate the attack. The EPSS score of less than 1% indicates that exploitation attempts have been rare to date, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network access to the HTTP interface and the cooperation of another user, which makes the exploitation straightforward from a remote environment that can reach the application gateway.
OpenCVE Enrichment