Impact
The vulnerability is an unauthenticated flaw that allows an attacker with network access via HTTP to create, delete, modify, or access critical data and potentially cause a partial denial of service. The flaw is easily exploitable and requires a human user other than the attacker to interact with the system, such as clicking a malicious link. If exploited, the attacker can alter or steal sensitive information and interrupt service for users. The impact spans confidentiality, integrity, and availability for any data accessible through Oracle WebCenter Content.
Affected Systems
Oracle WebCenter Content, part of Oracle Fusion Middleware, versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS base score of 9.6 indicates critical severity. The EPSS score of < 1% implies a very low probability of exploitation in the wild, though not zero. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the HTTP interface without credentials, but the need for human interaction (e.g., clicking a link) adds a detection or throttling barrier. The scope change indicates that exploitation may also affect additional Oracle products in the same environment, potentially expanding the impact surface. Overall, the risk remains high and warrants immediate attention.
OpenCVE Enrichment