Impact
The vulnerability exists in the Content Server component of Oracle WebCenter Content and allows an attacker who already has low‑privileged access on the infrastructure to compromise the WebCenter Content application. Successful exploitation leads to full takeover of the application, resulting in loss of confidentiality, integrity, and availability for all data managed by the instance.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue is specific to the Content Server component of these releases.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 signals a high severity vulnerability, with the vector indicating local access and low privileges required. The EPSS score is 0.00151, indicating a very low but nonzero exploitation probability, and the vulnerability is not yet listed in CISA KEV. The attack can be performed when an attacker has logged onto the machine where WebCenter Content runs; no external network vector is required.
OpenCVE Enrichment