Impact
The flaw resides in the Client Bundle component of Oracle WebCenter Enterprise Capture, permitting an unauthenticated attacker with HTTP network access to compromise the application. The vulnerability enables the attacker to create, delete, or modify critical data, read a subset of accessible data, and induce a partial denial of service. This represents an improper access control weakness, allowing both integrity violations and limited availability impacts.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The exploitation may also impact other Oracle Fusion Middleware products due to a scope change, but the primary target is the WebCenter Enterprise Capture application.
Risk and Exploitability
With a CVSS 3.1 Base Score of 9.9, the vulnerability is rated critical. The lack of authentication and the ability to target any HTTP accessible instance make it highly exploitable; however, an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can target the application remotely over the network without credentials, leveraging the exposed HTTP interface to achieve data tampering or partial denial of service. The high severity and wide attack surface underscore the urgent need for remediation.
OpenCVE Enrichment