Impact
A vulnerability in Oracle WebCenter Content allows an attacker with network access via HTTP and only low privileges to gain unauthorized access to all data exposed by the product. The flaw causes a scope change, enabling the attacker to reach system‑level confidentiality impact without requiring elevated permissions. Reported on CVSS 3.1 with a base score of 7.7, the vulnerability threatens the confidentiality of critical data.
Affected Systems
Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware’s Content Server component.
Risk and Exploitability
The CVSS score of 7.7 indicates a high risk to confidentiality. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote HTTP traffic, implying that any host able to reach the WebCenter Content instance could exploit the flaw. Because the privilege requirement is low, the risk to business data is significant, especially for organizations that expose WebCenter Content over public or shared networks.
OpenCVE Enrichment