Impact
This vulnerability in Oracle WebCenter Content allows an attacker who already has logged onto the host system, but without authentication to the application itself, to compromise the application and gain unrestricted access to all content data stored within it. The weakness appears to be an authorization defect that bypasses normal access controls, enabling the attacker to read highly confidential data. The impact is limited to confidentiality of data; integrity and availability are not affected. The weakness aligns with improper authorization principles.
Affected Systems
Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The product is part of Oracle Fusion Middleware, and the flaw is centered on the Content Server component. The components are commonly deployed in enterprise content management environments and may interoperate with other Oracle and non-Oracle applications, so successful exploitation could compromise additional data or systems.
Risk and Exploitability
The CVSS 3.1 base score is 7.1, indicating a high risk to confidentiality. The attack requires local system access but no application credentials, so it is relatively easy to exploit for anyone who can log on to the host. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog; however, the local nature of the attack and lack of mitigations make it a significant threat in environments where privileged access to the host is possible. An adversary could compromise the application and retrieve all stored data, potentially exposing sensitive or regulated information.
OpenCVE Enrichment