Impact
A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows an unauthenticated attacker with network access via HTTP to compromise the portal and gain full control, enabling the attacker to read, modify, or delete data and execute arbitrary requests. The flaw is an improper access control weakness (CWE-284) that can lead to loss of confidentiality, integrity, and availability of the application and its underlying data. Its severity is reflected in a CVSS 3.1 base score of 8.1, indicating a high-impact flaw if successfully exploited.
Affected Systems
The vulnerable Oracle WebCenter Portal releases are 12.2.1.4.0 and 14.1.2.0.0. Organizations running these versions should confirm that the latest patch or update from Oracle has been applied.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity. The EPSS score is reported as <1%, suggesting a low probability of exploitation, but the flaw still exposes a serious risk because it permits unauthenticated remote code execution via the HTTP interface, as the attacker does not need credentials. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread active exploitation has been reported yet, yet the potential impact and the availability of the exposed interface warrant immediate attention.
OpenCVE Enrichment