Impact
A flaw in Oracle WebCenter Portal’s Runtime Tools component permits an unauthenticated attacker with network access to a web interface to gain unauthorized access to the portal’s data. The vulnerability can be triggered through standard HTTP requests without prior authentication, resulting in disclosure of confidential information. The vulnerability’s severity is high, with a CVSS 3.1 score of 8.6, indicating a significant confidentiality impact while integrity and availability remain unaffected.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue originates in Oracle Fusion Middleware Runtime Tools and can extend to other integrated products due to a scope change, potentially impacting any product that utilizes the same portal framework.
Risk and Exploitability
The CVSS score of 8.6 reflects a severe risk, and the EPSS score of < 1% indicates a very low exploitation probability. Oracle does not list this vulnerability in the CISA KEV catalog. Attackers can exploit the flaw remotely by crafting HTTP requests; no authentication or privileged access is required, and the flaw can be exploited from any network location that reaches the web interface.
OpenCVE Enrichment