Impact
A flaw in Oracle WebCenter Content allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized access to critical data and, with human interaction from a user who is not the attacker, obtain the ability to read, insert, update or delete content. The vulnerability is specifically a permission escalation that can result in both confidentiality and integrity impacts, but it does not affect availability. The CVE description highlights that compromise can extend to other Fusion Middleware products due to a scope change. This type of weakness is reflected by the CWE identifiers for improper use of authorization controls.
Affected Systems
The vulnerability affects Oracle Corporation's WebCenter Content product. The affected releases are version 12.2.1.4.0 and 14.1.2.0.0. Because the flaw can change scope, systems that integrate with or depend on WebCenter Content may also be impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 indicates a high risk. The vector shows that attackers need network access via HTTP, low authentication privileges and user interaction; no active exploitation data is available (EPSS < 1% and not listed in CISA KEV). The requirement for another user to interact means that social‑engineering or phishing tactics may be necessary. Although the exploitation is not yet known to be widely active, the combination of a high inherent severity with a low exploitation probability means that mitigation should be prioritized now to prevent possible future attacks.
OpenCVE Enrichment