Impact
The vulnerability in Oracle WebCenter Content allows a low‑privileged attacker with remote HTTP access to elevate privileges or bypass authorization checks, resulting in unauthorized creation, modification, or deletion of critical data. The flaw requires a separate user’s interaction, implying that the attacker must persuade or trick a legitimate user to trigger the exploit. Successful exploitation would compromise confidentiality and integrity of all content stored in the affected WebCenter Content deployment, but it does not directly affect system availability. The CVSS 3.1 vector shows a network attack, low complexity, low privileges, user interaction, and high confidentiality and integrity impact.
Affected Systems
Affected versions include Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 released as part of Oracle Fusion Middleware. If your environment runs either of these releases and is reachable over the network, it is vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can gain unauthorized data access only after obtaining user interaction; however, in environments where employees routinely click external links, this risk is amplified. Once exploited, the attacker can alter or delete critical data, compromising business continuity and regulatory compliance.
OpenCVE Enrichment