Impact
Vulnerability in Oracle WebCenter Content's Content Server component allows an unauthenticated attacker with network access via HTTP to compromise the application. The weakness involves Cross‑Site Request Forgery (CWE‑352), Open Redirect (CWE‑601), and Cross‑Site Scripting (CWE‑79). An attacker does not need to authenticate, but a human interaction from a person other than the attacker is required to complete the attack. If successful, the attacker can take control of the Oracle WebCenter Content system, leading to loss of confidentiality, integrity, and availability. The CVSS 3.1 score of 8.8 reflects these severe impacts, with the vector indicating a network attack, low complexity, no privileges required, user interaction required, and scope unchanged.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. These versions are deployed in enterprise content management environments, and the vulnerability applies to the Content Server component accessed through HTTP endpoints.
Risk and Exploitability
The high CVSS score indicates significant risk, while the EPSS score of less than 1 % suggests that exploitation has not yet been widely observed. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires a user to interact with the application—such as clicking a malicious link—an attacker may rely on social engineering to gain a foothold. Once the user interacts and the vulnerability is triggered, the attacker can gain full control of the application with no authentication, resulting in a complete system takeover.
OpenCVE Enrichment