Impact
The flaw is a lack of required authorization in the Oracle WebCenter Content Content Server component, allowing an attacker who can reach the HTTP interface to create, delete, or alter critical data without any credentials. Because the vulnerability bypasses access controls, the attacker can also obtain read access to all data managed by the WebCenter Content instance, resulting in confidentiality and integrity compromises. This weakness is classified as CWE‑284, representing improper authorization controls. The vulnerability makes it possible to modify or exfiltrate data that the application is intended to protect, enabling a broad range of disruptive or exfiltrating attacks.
Affected Systems
Oracle WebCenter Content, offered by Oracle Corporation, contains affected versions 12.2.1.4.0 and 14.1.2.0.0. Users running either of these releases or any product that embeds the Content Server component are at risk, as the problem resides directly in the core content handling service.
Risk and Exploitability
The CVSS score of 8.7, combined with a scope change, indicates a high severity attack that expands beyond the affected application. The attack vector is inferred to be remote over HTTP, as the vulnerability description states that it is exploitable with network access via HTTP. No authentication, user interaction, or privilege is required, so any external host can launch an exploit. The EPSS score is less than 1 %, suggesting that exploitation attempts are currently rare, yet the high impact and wide accessibility mean that any organization using the vulnerable version should consider this a significant threat. The vulnerability is not listed in the CISA KEV catalog, but the presence of a scope change warrants close monitoring for potential cascading attacks into other components of the Oracle Fusion Middleware stack.
OpenCVE Enrichment