Impact
The vulnerability is a local privilege exploitation that allows a user with low-privileged access to bypass application access controls in Oracle WebCenter Content 14.1.2.0.0. Attackers can create, delete, or modify critical data, resulting in confidentiality and integrity loss. The weakness relates to insufficient authorization controls, matching CWE-284.
Affected Systems
Oracle WebCenter Content version 14.1.2.0.0, part of Oracle Fusion Middleware, is impacted. Users running this version on any infrastructure where local login access is available are at risk.
Risk and Exploitability
The CVSS 3.1 base score of 8.4 reflects a high severity. Exploitation requires local OS access with low privileged credentials and does not need user interaction, making it relatively easy to achieve in environments with shared or uncontrolled hosts. The EPSS score is extremely low, at less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the combination of high impact and ease of local exploitation warrants immediate attention.
OpenCVE Enrichment