Impact
The vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with HTTP network access to gain unauthorized access to critical data or gain full access to all accessible data. Successful exploitation requires the involvement of a human user distinct from the attacker and can result in unauthorized update, insert, or delete operations on data. The weakness stems from improper access control, enabling the attacker to bypass authentication checks.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 on Oracle Fusion Middleware are affected. The impacted component is the Content Server.
Risk and Exploitability
The CVSS 3.1 base score is 8.2 with an elevated confidentiality impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw over the network via HTTP, and while human interaction is required, the low attack complexity makes the risk significant for exposed systems.
OpenCVE Enrichment