Impact
The vulnerability resides in the Runtime Tools component of Oracle WebCenter Portal and permits a low‑privileged attacker with network access over HTTP to manipulate data. An attacker must convince another user to interact with the portal; once that occurs, the flaw can be used to create, delete, or modify any data that the portal has access to, resulting in severe confidentiality and integrity loss.
Affected Systems
Oracle WebCenter Portal, part of Oracle Fusion Middleware, is affected in versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS base score of 8.7 classifies this as high severity. The EPSS score is below 1%, indicating a low likelihood of exploitation at present, yet the vulnerability is immediately exploitable over the network with low privileges and requires only modest user interaction. The impact scope is changed, meaning compromised data could potentially affect other components exposed through the same interfaces. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment