Impact
The vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access over HTTP to create, delete, or modify critical data, leading to loss of data integrity and confidentiality. The flaw operates without requiring authentication or any privilege escalation, enabling a direct intrusion of the system's core data store. The impact could allow an attacker to undermine entire application content and to exfiltrate or corrupt sensitive information.
Affected Systems
Oracle WebCenter Content, versions 12.2.1.4.0 and 14.1.2.0.0, deployed in Oracle Fusion Middleware.
Risk and Exploitability
With a CVSS 3.1 base score of 7.4, the vulnerability poses a medium‑to‑high risk, giving attackers high confidentiality and integrity impact while availability remains unaffected. No exploitation probability score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the affected systems over HTTP from any external network point, making this a low‑effort, network‑based attack for anyone with internet connectivity to the target.
OpenCVE Enrichment