Impact
An access control flaw in Oracle WebCenter Portal lets an attacker who can reach the portal over HTTP gain read and write access to data without authenticating. The flaw requires a user other than the attacker to interact with the portal, such as clicking a crafted link, after which the request is treated as if it came from a legitimate user. The result is that confidential information can be disclosed and critical data can be altered or deleted, affecting the integrity and confidentiality of the portal’s data stores.
Affected Systems
Oracle Corporation’s WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Attacks against these versions can also impact other components of the Oracle Fusion Middleware stack, as the vulnerability can change the security scope beyond the portal itself.
Risk and Exploitability
Based on the description, it is inferred that the attacker can target any HTTP endpoint of Oracle WebCenter Portal from outside the organization, but successful exploitation requires a human (not the attacker) to interact with the portal – for example, by clicking a crafted link. Once that interaction occurs, the request is treated as if issued by an authenticated user, giving the attacker read or write access to portal data. The CVSS 3.1 base score of 8.2 reflects a high confidentiality impact and a lower integrity impact, with no availability impact. The EPSS score of less than 1% (0.00319) indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that widespread exploitation has not yet been observed. Nevertheless, the combination of a high severity score, the need for only HTTP access plus a vulnerable user, and the potential scope expansion to other Oracle Fusion Middleware components warrants a substantial risk assessment and prompt remediation.
OpenCVE Enrichment