Impact
A flaw in Oracle WebCenter Portal’s portlet services allows an unauthenticated user to exploit a weak access control mechanism. Because the vulnerability is reachable over HTTP, an attacker can gain full control of the portal, leading to complete loss of confidentiality, integrity and availability. The flaw is classified under CWE-284 and is reflected in a high CVSS 3.1 base score of 8.1.
Affected Systems
Oracle Corporation’s WebCenter Portal is affected, specifically the 12.2.1.4.0 and 14.1.2.0.0 releases. No other products or versions are listed as impacted.
Risk and Exploitability
The main risk level is moderate to high: the base score indicates severe impact, while the EPSS score of less than 1% suggests current exploitation potential is low. However, the vulnerability is relatively difficult to exploit yet offers complete takeover once successful. The attack vector is inferred to be network access via HTTP, typically from any net‑enabled client without needing prior authentication. The vulnerability is not yet listed in CISA KEV, but its impact warrants immediate attention.
OpenCVE Enrichment