Impact
Oracle WebCenter Enterprise Capture is vulnerable to an unauthenticated remote attack that enables an attacker with network access via T3 or IIOP to compromise the system. The flaw lies in the client bundle component, allowing a remote attacker to execute arbitrary actions and ultimately take over the application. The weakness can be categorized as an improper authentication failure, which can lead to total confidentiality, integrity, and availability loss.
Affected Systems
Oracle WebCenter Enterprise Capture from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 score of 9.8 indicates a critical severity. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based and requires no user interaction, giving an unauthenticated attacker with connectivity over T3 or IIOP a pathway to compromise the application. Given the high CVSS score but low EPSS, the overall risk of real-world attacks remains moderate, though the potential impact is severe.
OpenCVE Enrichment