Impact
Oracle WebCenter Portal is vulnerable to an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical portal data, and to gain unauthorized access to all data accessible through the portal. The vulnerability requires human interaction from a user other than the attacker and can result in serious confidentiality and integrity losses without any impact on availability.
Affected Systems
The flaw affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite. These are the only editions identified as vulnerable in the vendor’s advisory.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.7 indicates a high severity, reflecting high confidentiality and integrity impacts while availability is unaffected. EPSS score is less than 1% (0.00353), and the vulnerability is not listed in the CISA KEV catalog, so exact exploitation likelihood cannot be quantified, but the absence of a KEV listing does not imply low risk. The likely attack vector is network‑based via HTTP, and the vulnerability requires a cooperating user to trigger the action. The scope change indicates that successful exploitation could also affect additional Oracle products that interact with WebCenter Portal.
OpenCVE Enrichment