Impact
This vulnerability in the Composer component of Oracle WebCenter Portal allows an attacker with low privileges and network access via HTTP to achieve full control of the portal, affecting confidentiality, integrity, and availability. The problem appears to be an access‑control flaw that lets malicious requests bypass normal authorization, but this conclusion is inferred from the impact described in the CVE text.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Systems running these releases are at risk unless patched or otherwise mitigated.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attack can be launched remotely over HTTP by a low‑privileged user, and no user interaction is required. The likely attack path involves sending a crafted request to the Composer component that bypasses authorization controls to take over the portal.
OpenCVE Enrichment