Impact
The flaw is an access‑control weakness in the Runtime Tools component of Oracle WebCenter Portal that lets a low‑privileged attacker who can reach the service over HTTP create, delete, or modify portal data and read all data exposed by the portal. The vulnerability’s impact is loss of data integrity and confidentiality, enabling an attacker to alter or acquire critical information.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability resides in the Runtime Tools component of the Fusion Middleware suite and applies to the HTTP interface that these product versions expose.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high severity risk with significant confidentiality and integrity impacts. Exploitation requires only network access over HTTP and a low‑privileged account, which an attacker can obtain with minimal effort if the portal is exposed. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV; nevertheless, the ease of exploitation and the breadth of data exposure make the threat substantial. The likely attack vector is HTTP traffic, inferred from the description that the attacker has network access via HTTP.
OpenCVE Enrichment