Impact
Oracle WebCenter Portal’s Portlet Services component contains a flaw that allows attackers who have network connectivity and do not need privileged credentials to execute arbitrary actions within the portal. The vulnerability can be triggered through crafted HTTP requests, resulting in a complete takeover of the portal instance. An attacker who successfully exploits this flaw can read, modify, or delete data, and potentially disrupt the portal’s availability. The impact covers confidentiality, integrity, and availability and is classified as Remote Compromise of the application.
Affected Systems
Oracle WebCenter Portal, versions 12.2.1.4.0 and 14.1.2.0.0, distributed as Oracle Fusion Middleware. The vulnerability is present in the Portlet Services component of these releases.
Risk and Exploitability
The high CVSS Base Score of 8.8 reflects severe remote code execution potential, while an EPSS score of < 1% indicates a low but non-zero probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests over a network that has access to the portal, requiring only low privilege and no prior authentication. Detection relies on monitoring for anomalous portlet activity and HTTP request patterns.
OpenCVE Enrichment