Impact
Oracle WebCenter Portal contains an unauthenticated remote vulnerability that allows an attacker with network access via HTTP to compromise the portal. The flaw is an improper access control issue (CWE-284) that enables the attacker to read all data exposed by the portal, potentially exposing critical information. This breach of confidentiality can occur without any authentication or special privileges.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability may also affect other related Oracle Fusion Middleware components due to scope changes as noted in the advisory.
Risk and Exploitability
The CVSS 3.1 Base Score is 8.6, indicating a high severity of potential data exposure. The EPSS score is 0.00303 (<1%), indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw simply by connecting to the web interface over HTTP with no authentication, making it easily exploitable. The scope change expands the risk, potentially affecting additional Oracle products that integrate with WebCenter Portal.
OpenCVE Enrichment