Impact
This vulnerability permits an unauthenticated attacker who can reach the system over HTTP to create, delete or modify content in Oracle WebCenter Content. The flaw resides in the Content Server component and effectively bypasses normal access controls, granting the attacker the same privileges as a legitimate user, thereby compromising confidentiality and integrity of stored data.
Affected Systems
Affected products include Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0, both part of Oracle Fusion Middleware. The vulnerability is present across these releases and may also influence other WebCenter or Fusion Middleware components if they share authentication mechanisms.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 reflects high severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is over the public network via HTTP by exploiting the lack of authentication checks in the Content Server, and because the flaw changes the scope to all content, a successful exploit can give the attacker full access to all stored data in affected WebCenter Content instances.
OpenCVE Enrichment