Impact
The flaw resides in the Client Bundle component and stems from a combination of weak authentication (CWE‑287) and authorization (CWE‑284, CWE‑269) controls, as well as insecure privilege validation (CWE‑306). An attacker with low privilege and network access can send a crafted HTTP request to the exposed endpoint and gain full control over the Oracle WebCenter Enterprise Capture application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is triggered through the Client Bundle interface exposed over HTTP.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, and the EPSS score is less than 1 %, indicating a rare but possible exploit. The flaw is not listed in CISA KEV yet its remote and low‑privilege nature makes it a serious threat. Exploitation requires only forming a valid HTTP request; no special conditions or user interaction are needed.
OpenCVE Enrichment