Impact
The Oracle WebCenter Portal Portlet Services component contains an improper access control flaw that allows an unauthenticated attacker who can reach the portal over HTTP to obtain full access to all portal data or induce repeated crashes, resulting in both confidentiality compromise and availability loss. The associated weakness aligns with CWE-284 and is reflected in a CVSS 3.1 base score of 9.1.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, which belong to the Oracle Fusion Middleware family. The vulnerability is exploitable through standard HTTP requests without any authentication or privileged input.
Risk and Exploitability
The high CVSS score of 9.1 indicates severe risk, and the absence of authentication or additional controls means the flaw is readily exploitable. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the potential for complete data loss or denial of service makes it a critical threat to any organization using the affected portal releases.
OpenCVE Enrichment