Impact
Oracle WebCenter Content is vulnerable to a difficult‑to‑exploit flaw that permits an unauthenticated attacker with network access over HTTP to compromise the system. The attack requires human interaction from a user other than the attacker and, if successful, can result in a full takeover, affecting confidentiality, integrity, and availability. The vulnerability is reflected in a CVSS 3.1 base score of 7.5 with the vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.
Affected Systems
Affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. Only installations of these releases are subject to the flaw.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is high severity, yet the EPSS score of less than 1 % indicates a low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The exploitation path requires the victim to provide interaction, typically through an HTTP request, making the attack scenario constrained but still plausible for targeted campaigns.
OpenCVE Enrichment