Impact
The vulnerability allows a low‑privileged attacker with network access via HTTP to take full control of Oracle WebCenter Content, affecting confidentiality, integrity and availability. This flaw is due to an improper authorization mechanism that permits unauthorized users to perform privileged actions, classified as a high‑severity remote takeover. The potential impact includes data exposure, modification, and denial of service for all content managed through the application.
Affected Systems
Oracle Corporation’s WebCenter Content product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are used by organizations to manage web content. The flaw exists in the Web Content Management component, and any deployment of the specified versions is vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates a high level of risk, while the EPSS score of less than 1% shows a low probability of exploitation. It is not listed in the CISA KEV catalog, but attackers could exploit this weakness over standard HTTP connections, requiring only low privileges to succeed. Successful exploitation would grant an attacker complete takeover of the application.
OpenCVE Enrichment