Impact
The flaw exists in the Client Bundle component of Oracle WebCenter Enterprise Capture, where insufficient access control permits a low‑privileged user with network access over HTTP to obtain full control of the application. The attacker can read, modify, or delete captured data, submit new captures, and reconfigure the system, leading to a complete takeover that compromises confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected; the vulnerability resides in the Client Bundle component.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity across all impact dimensions. The EPSS score of < 1% indicates only a very low but non‑zero likelihood of exploitation in active campaigns. The vulnerability is not listed in the CISA KEV catalog. Attacks require only network access via HTTP and a low‑privileged user, with no user interaction needed, lowering the entry threshold for adversaries.
OpenCVE Enrichment