Impact
The vulnerability allows an unauthenticated attacker to connect via the T3 or IIOP protocols to the Client Bundle component of Oracle WebCenter Enterprise Capture and execute arbitrary code. Successful exploitation results in the attacker taking full control of the application, compromising confidentiality, integrity, and availability of the entire system. The weakness is reflected in a CVSS 3.1 base score of 9.8, indicating a critical severity and the potential for full system takeover.
Affected Systems
The weakness affects Oracle WebCenter Enterprise Capture for the identified versions 12.2.1.4.0 and 14.1.2.0.0. No other versions or products are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 9.8 denotes a critical risk, while the EPSS score is not available and the vulnerability does not appear in the CISA KEV catalog. The attack vector is network based (T3 and IIOP) and requires no authentication, meaning an attacker with network access can immediately attempt exploitation. The high severity, lack of requirement for user interaction, and unrestricted attacker control make the risk of exploitation significant if the vulnerability remains unpatched.
OpenCVE Enrichment