Impact
This CVE describes a flaw in Oracle WebCenter Portal that enables a low-privileged attacker with network access via HTTP to bypass authorization controls and gain unauthorized read, write, and partial denial-of-service capabilities. The vulnerability can be triggered without authentication, allowing an attacker to obtain critical data or modify/delete portal content. The weakness corresponds to improper access control (CWE-284), forming the root cause of the unauthorized privileges and intrusion risk.
Affected Systems
Oracle Corporation’s WebCenter Portal product is affected in versions 12.2.1.4.0 and 14.1.2.0.0, as part of the Oracle Fusion Middleware stack. Administrative users may have deployed these releases in their environments, and any instance of WebCenter Portal running these versions is vulnerable. No other product variants or components are listed as impacted by this advisory.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity due to confidentiality, integrity, and availability impact. Without an EPSS estimate, the exploitation probability is unknown, but the vulnerability is considered easily exploitable by a network attacker with standard HTTP access. It is not listed in the CISA KEV catalog, yet the risk remains significant given the urgent ability to compromise portal data and degrade service. An attacker could initiate unauthorized operations with minimal privileges, potentially escalating to broader compromise if the portal integrates with other internal systems.
OpenCVE Enrichment