Impact
Vulnerability in the Oracle WebCenter Portal Composer component allows an attacker with low privileges who can reach the RMI interface over the network to compromise the portal. Successful exploitation results in the attacker gaining full control of the WebCenter Portal, thereby compromising confidentiality, integrity, and availability of the hosted applications and data.
Affected Systems
Affected are Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, as specified by the advisory and the corresponding CPE entries.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high risk. The EPSS score of < 1% signals that the likelihood of exploitation is very low but not zero, and the vulnerability is not yet listed in the CISA KEV catalog, implying no widespread exploitation to date. The likely attack vector is via the public RMI service; any remote host with access to that port can attempt the exploit.
OpenCVE Enrichment