Impact
The vulnerability in Oracle WebCenter Content arises from an overly permissive access control that permits any unauthenticated user with network access via HTTP to create, delete, or modify critical data. This flaw, identified as a CWE-284 access control weakness, can be exploited without authentication or privilege escalation, leading to confidentiality and integrity violations of data stored in the Content Server.
Affected Systems
The flaw affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. Because the vulnerability includes a scope change, other components of the Oracle Fusion Middleware suite that rely on the Content Server may also be impacted.
Risk and Exploitability
The vulnerability has a CVSS base score of 8.7, indicating high severity, yet the EPSS score is less than 1%, suggesting a very low probability that the flaw is currently being actively exploited. The flaw is not listed in the CISA KEV catalog, further indicating limited known exploitation. Exploitation requires the target to be exposed via HTTP and does not require authentication, so any publicly accessible instance could be a potential target if an attacker is able to send crafted HTTP requests. The overall risk is higher for highly exposed systems, but the likelihood of exploitation remains low based on current metrics.
OpenCVE Enrichment