Impact
A remotely exploitable flaw in Oracle WebCenter Content allows a low privileged attacker with network connectivity via HTTP to gain unauthorized data manipulation capabilities. The vulnerability, a CWE‑306 Missing Authentication for Critical Function, grants the attacker the ability to create, delete, or alter critical content, compromising both the confidentiality and integrity of the data managed by the system. The impact is limited to the data within the affected WebCenter Content installation.
Affected Systems
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 are affected, both part of Oracle Fusion Middleware’s Web Content Management components accessible over HTTP.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity with significant impacts on confidentiality and integrity. The EPSS score is less than 1%, implying a low probability of exploitation in the wild at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network attacker leveraging an HTTP connection to the WebCenter Content instance. Successful exploitation requires low network access and low privileges, making the flaw easily exploitable in environments without stringent network controls.
OpenCVE Enrichment