Impact
A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access to compromise the system via HTTP. The flaw enables unauthorized access to critical data or all content accessible to the application, resulting in a high confidentiality impact. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects that the attack requires only network connectivity and no user interaction.
Affected Systems
The affected product is Oracle WebCenter Content with Oracle Fusion Middleware version 12.2.1.4.0 and 14.1.2.0.0. These specific releases are listed as vulnerable in Oracle's security alert.
Risk and Exploitability
An attacker operating on a network that can reach the WebCenter Content HTTP interface can exploit this weakness without authentication. The CVSS Base Score of 7.5 indicates substantial risk, but no Exploit Probability Score is available and the vulnerability is not currently listed in CISA's KEV catalog. The likely attack vector is HTTP traffic, and successful exploitation would grant the attacker access to confidential data stored within the application.
OpenCVE Enrichment