Impact
A flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture allows an unauthenticated attacker with network access to exploit the Java RMI interface. Successful exploitation can lead to takeover of the WebCenter Enterprise Capture instance, compromising the confidentiality, integrity, and availability of the application and its data.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is confined to the Client Bundle module of this product.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical severity. The EPSS score of < 1% (specifically 0.00486) indicates a very low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote over the network via RMI, requiring no authentication, which still requires vigilance in environments exposed to external networks.
OpenCVE Enrichment