Impact
A flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture allows an unauthenticated attacker to send crafted HTTP requests that bypass authentication and grant full control over the application. The weakness aligns with CWE‑306 Missing Authentication. Successful exploitation permits the attacker to read, modify, or delete critical data and disrupt the system, affecting confidentiality, integrity, and availability.
Affected Systems
Versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Enterprise Capture are affected. The product runs as part of Oracle Fusion Middleware and exposes an HTTP endpoint through its client bundle. It is inferred that deployments exposing this HTTP interface to the network are at risk; the data does not explicitly state whether the interface is exposed.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 classifies the issue as Critical. The EPSS score is below 1%, indicating that widespread exploitation is unlikely currently. However, the vulnerability requires only unauthenticated HTTP traffic and no privileged access, making the attack path straightforward. The flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP traffic to the exposed service, inferred from the description that the issue is exploitable via the web interface.
OpenCVE Enrichment