Impact
An incorrect access control flaw exists in the Runtime Tools component of Oracle WebCenter Portal. The flaw, categorized as CWE‑284, allows an attacker to send crafted HTTP requests without authentication and gain full control of the portal. Successful exploitation would lead to a complete compromise, exposing all stored data, allowing arbitrary code execution, and disrupting portal availability.
Affected Systems
The affected installations are Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.
Risk and Exploitability
The vulnerability is rated with a CVSS v3.1 base score of 9.8, indicating a critical impact on confidentiality, integrity, and availability. The EPSS indicates a probability below 1%, so active exploitation attempts are unlikely at present, and the flaw is not currently included in CISA's KEV portfolio. Exploitation requires only network access to the portal’s HTTP interface; no credentials or out‑of‑band requirements are needed. If an attacker succeeds, they can completely take over the system, so the risk remains high.
OpenCVE Enrichment