Impact
Oracle WebCenter Portal is affected by an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to compromise the portal. Successful exploitation can lead to complete takeover, resulting in loss of confidentiality, integrity, and availability for portal data and services. The description indicates that the vulnerability can be triggered with minimal attacker privileges and without user interaction; it is inferred that the weakness possibly involves improper access control or authentication mechanisms.
Affected Systems
Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware’s Runtime Tools, are the only products directly impacted by this CVE. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS Base Score of 8.8 indicates a high severity, and the EPSS score of <1% indicates that the overall exploitation probability is very low, though the vulnerability is technically easily exploitable via remote HTTP access with low privilege. Because the flaw is not listed in the CISA KEV catalog, no documented active exploits are known, but the combination of high impact and exposed HTTP interface warrants proactive mitigation. The likely attack path is through unauthenticated or low‑privileged HTTP requests that bypass proper access control, allowing takeover of the portal.
OpenCVE Enrichment