Impact
The Oracle WebCenter Content product contains a vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation requires human interaction from a third party and can result in unauthorized update, insertion or deletion of data, unauthorized read access to a subset of content, and a partial denial of service. The impact spans confidentiality, integrity, and availability as defined by the CVSS v3.1 score of 7.1.
Affected Systems
Affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, as listed by the CNA. No other Oracle products are mentioned in the official description as directly impacted, though the CVE notes that attacks may significantly affect additional products through scope changes.
Risk and Exploitability
The CVSS score indicates a medium‑high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request sent over the network; the requirement of human interaction suggests a social‑engineering component. Given these factors, the risk of exploitation is moderate to high in exposed environments, and the potential impact could affect data integrity, confidentiality, and service availability.
OpenCVE Enrichment