Impact
A vulnerability in Oracle WebCenter Content allows a low‑privileged attacker with network access via HTTP to compromise the platform. The flaw requires a user other than the attacker to provide human interaction, yet a successful exploit can lead to full takeover of the instance, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
The affected product is Oracle WebCenter Content for Oracle Fusion Middleware. Versions 12.2.1.4.0 and 14.1.2.0.0 are impacted.
Risk and Exploitability
The CVSS v3.1 base score is 7.1, indicating high severity. The EPSS score is 0.0031 (<1%), and the vulnerability is not listed in the CISA KEV catalog. An attacker must reach the HTTP interface, be low‑privileged, and rely on a separate user to interact, which reduces the likelihood of exploitation but does not eliminate it. The impact is severe if exploitation succeeds.
OpenCVE Enrichment