Impact
The vulnerability in Oracle WebCenter Content allows an attacker with network access through HTTP to compromise the application without authentication. Successful exploitation can lead to full takeover, resulting in loss of confidentiality, integrity, and availability. The weakness is an improper authorization flaw (CWE-284).
Affected Systems
The affected products are Oracle WebCenter Content for Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests low current exploitation probability, though the vulnerability is not listed in CISA KEV. The likely attack vector is a remote HTTP connection from the open network; based on the description, it is inferred that the attacker will need to interact with a user other than themselves to complete the exploit.
OpenCVE Enrichment