Impact
A flaw in the client bundle of Oracle WebCenter Enterprise Capture allows an attacker to connect to the RMI interfaces without authentication. By sending specially crafted requests, an unauthenticated remote user can gain control of the application, resulting in the exposure of all confidential data, modification of system state, and disruption of services. The vulnerability carries full confidentiality, integrity, and availability impacts as reflected in the CVSS vector.
Affected Systems
This weakness affects Oracle Corporation’s WebCenter Enterprise Capture, specifically versions 12.2.1.4.0 and 14.1.2.0.0. No additional products or versions were identified as impacted.
Risk and Exploitability
With a CVSS v3.1 base score of 9.8, the risk is critical. EPSS has not been published but the lack of an exploit restriction implies high exploitability. The vulnerability is not listed in CISA’s KEV catalog. Attackers who can reach the RMI ports from the network can exploit this weakness with no prior privileges, making it a high‑threat scenario.
OpenCVE Enrichment