Impact
A vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle permits an unauthenticated attacker with network access over HTTP to compromise the application, potentially leading to a complete takeover of the system. The flaw carries severe confidentiality, integrity, and availability impacts, reflected in a CVSS 3.1 Base Score of 8.1. The vulnerability is difficult to exploit but, once successful, it allows attackers to control the WebCenter Enterprise Capture instance entirely.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are used by organizations to capture and manage web content.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score of less than 1% suggests low probability of widespread exploitation at this time. The vulnerability is not listed in CISA KEV. The likely attack vector involves an unauthenticated attacker exploiting the vulnerability over HTTP, requiring no user interaction or elevated privileges.
OpenCVE Enrichment