Impact
The flaw resides in the Runtime Tools component of Oracle WebCenter Portal and allows a low‑privileged attacker who can reach the system over HTTP to gain complete control of the portal. Successful exploitation can lead to takeover, exposing, altering, or denying the portal’s data. The weakness pertains to improper access control (CWE‑284).
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are impacted.
Risk and Exploitability
The CVSS v3.1 score of 8.5 indicates high confidentiality, integrity, and availability impact. EPSS is < 1% and the vulnerability is not currently listed in the CISA KEV catalog. The low‑privilege requirement and the need for only network‑based HTTP access suggest that external attackers could potentially reach the target from outside the organization. An attacker would likely need to send a specially crafted HTTP request; upon success they could execute arbitrary code or otherwise control the portal.
OpenCVE Enrichment