Impact
A vulnerability in Oracle WebCenter Portal (Component: Runtime Tools) allows an attacker with network access over HTTP and low privileges to trigger an action requiring another user’s interaction. The flaw enables the attacker to obtain unauthorized access to critical data and to update, insert, or delete portal data. The impact includes a high confidentiality loss and a low integrity breach, as indicated by the CVSS 3.1 vector (C:H/I:L). The weakness is an improper access control flaw.
Affected Systems
The issue affects Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0. Due to the scope change, other integrated Oracle Fusion Middleware products could also be impacted when the portal is compromised.
Risk and Exploitability
The CVSS base score of 7.6 highlights moderate to high risk. The EPSS score of <1% indicates a low, but non‑zero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the portal’s HTTP interface, low privileges on the target system, and the cooperation of a non‑attacker user to exploit the flaw. Given these conditions, the likelihood is moderate, but the potential for significant data breach makes timely mitigation crucial.
OpenCVE Enrichment