Impact
A flaw in Oracle WebCenter Portal allows any unauthenticated user to reach the portal via HTTP and perform data operations—a flaw described as a denial of formal authentication (inferred). The vulnerability lets an attacker create, delete, or modify portal data without credentials, leading to forced changes to sensitive information and overall degradation of data integrity. The attack may extend beyond the Portal, potentially affecting other components of Oracle Fusion Middleware, as the reported scope change permits additional products to be impacted.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Any deployment of these exact versions that accepts external HTTP connections is vulnerable, regardless of the environment in which the portal runs.
Risk and Exploitability
The CVSS vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N yields a base score of 8.7, indicating high confidentiality and integrity impact. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The attacker needs only network access to the portal’s HTTP interface and no login credentials, which makes exploitation plausible for any externally exposed instance. The potential for widespread unauthorized data manipulation and the possible cross‑component scope expansion make this flaw a significant threat.
OpenCVE Enrichment