Impact
A vulnerability exists in Oracle WebCenter Content’s Content Server component that allows an unauthenticated attacker with physical network connectivity to the host machine to create, delete or modify critical data and gain unauthorized access to all data stored by the application. The flaw impacts confidentiality and integrity, enabling the attacker to alter or destroy content without authentication.
Affected Systems
Affected are Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is specific to the Oracle Fusion Middleware stack that hosts the Content Server.
Risk and Exploitability
The CVSS v3.1 base score is 8.0, indicating high severity, while the attack vector is local (adjacency). The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploitation requires physical or local network access, the likelihood of attack is limited to environments with compromised LAN segments or insider threat scenarios, but once achieved the attacker can permanently alter or exfiltrate critical data.
OpenCVE Enrichment