Impact
Oracle WebCenter Portal is vulnerable to remote exploitation through HTTP requests. An unauthenticated attacker can gain unauthorized creation, deletion or modification of critical data or all portal data, and can trigger a partial denial of service. The flaw is classified as a remote flaw with significant integrity and availability consequences, as reflected in the CVSS Base Score of 7.1.
Affected Systems
Affected systems include Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, as listed in the Oracle security alert. Patch status is not detailed in the available data.
Risk and Exploitability
The CVSS vector AV:N/AC:L/PR:N/UI:R indicates that a network attacker can exploit the vulnerability without authentication, but human interaction from a user other than the attacker is required to complete the attack. The EPSS score of <1% indicates a very low probability of exploitation, although insufficient data may still exist. The vulnerability is not listed in CISA’s KEV catalog, indicating no public evidence of active exploitation.
OpenCVE Enrichment