Impact
This vulnerability in Oracle WebCenter Content permits a low‑privileged attacker with network access over HTTP to compromise the application. Exploitation requires the attacker to persuade a third‑party user to perform an action, after which the application can be taken over, resulting in full confidentiality, integrity, and availability impact.
Affected Systems
Affected are Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, deployed in enterprise document management environments.
Risk and Exploitability
The CVSS score of 8.0 signals high impact, while the EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The vulnerability can be leveraged by an attacker who has network reach to the WebCenter Content HTTP endpoint and can convince an unrelated user to complete an operation. The presence of publicly disclosed exploits is not reported in the CVE payload, and the product is not listed in the CISA KEV catalog, but the potential for application takeover remains significant. Rapid patching is strongly advised.
OpenCVE Enrichment