Impact
The vulnerability resides in the Composer component of Oracle WebCenter Portal, enabling a low‑privileged attacker with network access over HTTP to compromise the portal. The flaw can be exploited from a remote network, and successful exploitation leads to full takeover of the portal instance, impacting confidentiality, integrity, and availability. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates a remote attack with low effort and controls various security properties.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are exposed to HTTP traffic.
Risk and Exploitability
The CVSS base score of 9.9 categorizes the flaw as critical. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential impact. Since the attack vector is network‑based HTTP access and the attacker only requires low privileges, the likelihood of exploitation is high in environments where the portal is accessible from the internet or untrusted networks. The scope change indicates that additional products may be impacted if the portal is integrated with them.
OpenCVE Enrichment