Impact
An easily exploitable flaw in Oracle WebCenter Content’s Web Content Management component allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can affect confidentiality, integrity, and availability, ultimately enabling a remote attacker to take complete control of the affected system. The vulnerability grants low privilege but the impact expands to the entire application, and, because the scope of the vulnerability changes, other products within the environment may also be at risk.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS base score of 9.9 indicates critical severity. The EPSS score of less than 1% shows that active exploitation is currently rare, but the attack can be carried out remotely via standard HTTP traffic, requiring no special privileges. The vulnerability is not listed in CISA’s KEV catalog, yet the high impact and remote nature warrant immediate attention. The likely attack vector is an unauthenticated or minimally privileged HTTP request to the WebCenter Content service, enabling full takeover after exploitation.
OpenCVE Enrichment