Impact
A flaw in the client bundle of Oracle WebCenter Enterprise Capture allows an attacker to connect to the RMI interfaces without any authentication. By sending specially crafted requests, an unauthenticated opponent can gain complete control of the application, which leads to loss of confidentiality, integrity and availability of the captured data and the underlying services.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other products or releases are currently identified as impacted.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 9.8, indicating critical severity. The EPSS score of 0.0045 indicates a very low likelihood of exploitation in the general threat landscape, though the lack of authentication and network‑accessible RMI interface makes it plausible for an adversary with network access. The vulnerability is not listed in CISA’s KEV catalog. Attackers with network access to the RMI port can exploit this weakness without any prior privileges, enabling a full compromise of the application.
OpenCVE Enrichment