Impact
The vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with HTTP network access to bypass authentication checks and read or modify critical data within the Content Server component. Successful exploitation results in confidentiality compromise and, depending on the requested operation, potential integrity modifications. The flaw requires that a user distinct from the attacker initiate the HTTP request, meaning attacker action is limited to persuading an insider to perform the request. The weakness stems from improper access control (CWE-284).
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable; the flaw resides in the Content Server component.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 highlights high severity, with a high confidentiality impact and a low integrity impact; the scope change indicates that the vulnerability can affect resources beyond the initially affected component. The EPSS score is less than 1%, showing a low probability of exploitation in the wild, but the vulnerability is not listed in the CISA KEV catalog. Attackers may exploit the flaw over the network through HTTP; although human interaction is required, the low attack complexity and lack of authentication make the risk significant for exposed systems.
OpenCVE Enrichment