Impact
This vulnerability permits a low‑privileged attacker with network access via HTTP to gain unauthorized access to all data available in an Oracle WebCenter Portal instance. The flaw resides in the Runtime Tools component and can lead to data compromise because it bypasses established access controls. The impact is a confidentiality breach, as indicated by the CVSS vector, with no denial of service or integrity impact noted.
Affected Systems
The affected product is Oracle WebCenter Portal, version 14.1.2.0.0 of Oracle Fusion Middleware. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS base score is 7.7, reflecting significant confidentiality risk. The EPSS score of 0.0027 indicates a very low but non‑zero exploitation probability, meaning the vulnerability is still potentially exploitable despite the low likelihood. The CVE is not listed in the CISA KEV catalog, but the potential for widespread data exposure warrants a prioritized response. Attacks may be launched over the public network, so the primary vector is network‑based HTTP.
OpenCVE Enrichment