Impact
A flaw in Oracle WebCenter Content permits an attacker who can reach the system over HTTP, even with low privileges, to fully compromise the Web Content Management component. By exploiting this weakness the attacker can execute code and seize control of the application, leading to loss of confidentiality, integrity, and availability. It is inferred from the associated CWEs that the issue involves authorization and authentication weaknesses, although the description does not detail the exact mechanisms.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These installations are part of Oracle Fusion Middleware and become vulnerable when the Web Content Management component is exposed to network traffic.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high‑impact vulnerability capable of compromising all core properties of the application. The EPSS score is below 1 %, signaling a very low current exploitation probability, and the flaw is not listed in CISA’s KEV catalog. Attackers only need network access to the HTTP interface; the description does not specify whether additional credentials are required, so that condition remains unknown. This makes the issue high risk for environments that expose the service to untrusted networks.
OpenCVE Enrichment