Impact
The flaw resides in the Content Server component of Oracle WebCenter Content and allows an attacker who can reach the HTTP interface to obtain unauthenticated access. Although successful exploitation requires the involvement of a user other than the attacker, an authenticated victim can then view, insert, update or delete content that should be restricted. The primary impact is loss of confidentiality and integrity for critical data stored within WebCenter Content.
Affected Systems
Oracle WebCenter Content, version 12.2.1.4.0 and version 14.1.2.0.0, is affected. These releases are part of Oracle Fusion Middleware and are delivered by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a high severity, with high confidentiality impact and low integrity impact. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack path is remote over HTTP, with the attacker leveraging the ability to reach the content server without authentication. Attackers would need to convince a human user to perform an action that satisfies the vulnerability’s requirement for non‑attacker interaction to achieve the unauthorized data access or modification.
OpenCVE Enrichment