Impact
The vulnerability is located in the Composer component of Oracle WebCenter Portal and allows an attacker with low privileges and network access over HTTP to compromise the portal. An attacker can gain full control of the application, resulting in loss of confidentiality, integrity, and availability. The weakness is a classic access‑control flaw (CWE‑284).
Affected Systems
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 are affected. The product is part of Oracle Fusion Middleware. No other products are explicitly listed as impacted, though the description notes that attacks may affect additional products due to scope change.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates a severe vulnerability. The EPSS score is reported as < 1%, suggesting that exploitation is unlikely to be seen in the wild. The vulnerability is not in the CISA KEV catalog, but its high impact means it must be addressed promptly. The likely attack vector is over the network via HTTP, and the requirement of low privileges means many internal users or systems that can reach the portal are potential attackers.
OpenCVE Enrichment