Impact
A flaw in Oracle WebCenter Portal’s portlet services enables unauthenticated attackers with network access via HTTP to compromise the portal. Successful exploitation permits attackers to create, delete, or modify access controls and to read or alter critical portal data, violating confidentiality and integrity. The vulnerability is classified as a high‑severity risk with a CVSS score of 9.1.
Affected Systems
Oracle Corporation’s Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are affected. These versions are part of Oracle Fusion Middleware and are commonly deployed in enterprise portal environments.
Risk and Exploitability
The CVSS base score of 9.1 indicates significant impact, while the EPSS score of less than 1% suggests a low current exploitation probability. The attack vector is network‑based over HTTP with no authentication required, meaning an attacker can initiate the exploit from any location that can reach the portal. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high impact and low but nonzero exploitation risk warrants immediate mitigation.
OpenCVE Enrichment