Impact
Vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an unauthenticated attacker with network access via HTTP to fully compromise the application, resulting in loss of confidentiality, integrity, and availability for the entire system. The flaw enables an attacker to take over the application without needing any prior credentials, effectively granting remote code execution capabilities.
Affected Systems
Affected by Oracle WebCenter Enterprise Capture, a product of Oracle Corporation, the flaw is present in the Client Bundle component of versions 12.2.1.4.0 and 14.1.2.0.0, both part of Oracle Fusion Middleware.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 9.8, indicating critical severity. An EPSS score of <1% suggests a low probability of exploitation, but the attack requires only HTTP connectivity and no authentication, implying that an attacker could readily abuse it. The vulnerability is not listed in the CISA KEV catalog, yet its severity, ease of exploitation, and remote nature warrant urgent remediation.
OpenCVE Enrichment