Impact
This vulnerability, identified as a CWE-284 Improper Access Control flaw, permits an unauthenticated attacker with network access to HTTP to compromise Oracle WebCenter Content. Successful exploitation allows the attacker to create, delete, or modify critical data and to gain full unauthorized access to all data that the product hosts. The vulnerability may also affect other Oracle Fusion Middleware components because the scope can change.
Affected Systems
Oracle WebCenter Content version 12.2.1.4.0 and version 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑impact vulnerability. The exploit requires only network access and does not need user interaction. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in KEV, suggesting it is not currently known to be actively exploited in the wild. However, the high severity and unauthenticated nature warrant close attention.
OpenCVE Enrichment