Impact
Oracle WebCenter Content implements an improper access control that permits a low-privileged attacker with HTTP network access to read, insert, update or delete data beyond its intended scope. Based on the description, it is inferred that no user interaction is required, and the attacker can gain unauthorized read and modification access to confidential documents. This flaw carries a CVSS 3.1 base score of 7.1, indicating high confidentiality impact and lower integrity impact, and it includes a scope change that may affect other Oracle products linked to the content server.
Affected Systems
Vulnerable versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. These deployments are typically part of larger Oracle Fusion Middleware environments; as such, an attacker who compromises the content server could also compromise other components that rely on the same data store or services that interact with WebCenter Content.
Risk and Exploitability
The likely attack vector is HTTP network traffic from a low-privileged account, as inferred from the description. Exploitation requires only this network access and no user interaction. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no public exploits are known. However, the CVSS score of 7.1 and the scope change suggest the potential for significant impact if the access control weakness is present in related applications. Organizations should promptly apply the vendor patch, or if not yet available, restrict HTTP traffic to trusted IPs and review user permissions.
OpenCVE Enrichment