Impact
An unauthenticated attacker with network access to the T3 and IIOP interfaces can exploit a Weak Authentication or Authorization flaw (CWE-284) in the client bundle of Oracle WebCenter Enterprise Capture, leading to complete takeover of the application. The vulnerability results in confidentiality, integrity, and availability loss, as described by the CVSS 3.1 score of 9.8, and allows the attacker to execute arbitrary code in the context of the application.
Affected Systems
Oracle Corporation’s WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are identified as affected. These versions are part of Oracle Fusion Middleware and are typically deployed in enterprise content capture scenarios.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical risk, and the EPSS score of < 1% indicates a very low exploitation probability. Nonetheless, the vulnerability is easily exploitable with network connectivity to T3 and IIOP ports, and there is no mention of the vulnerability being listed in KEV. Attackers could therefore mount attacks without authentication, leading to full control over the application.
OpenCVE Enrichment