Impact
The vulnerability in Oracle WebCenter Content allows a low‑privileged attacker who can reach the application over HTTP to create, delete, or modify data that is normally protected. As a result, confidential data can be compromised and the integrity of content stored in the system can be altered, potentially leading to loss of critical information or service disruption. The weakness is classified as an improper access control flaw.
Affected Systems
Affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. The product is part of Oracle Fusion Middleware and is deployed by organizations that provide web‑based document management and collaboration services.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates a high severity with significant confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild at this time, and it is not listed in CISA’s KEV catalog. Successful exploitation, however, requires network access to the HTTP port of WebCenter Content and a secondary action from a user other than the attacker, implying that human interaction or social engineering may be needed. If achieved, the attacker gains unauthorized access to sensitive data and can modify or delete critical information, potentially compromising other connected products due to the scope change indicated by the CVSS vector.
OpenCVE Enrichment