Impact
This vulnerability is an authentication bypass flaw (CWE-287) combined with a missing authentication weakness (CWE-306) in the portlet services of Oracle WebCenter Portal. An unauthenticated attacker who can reach the portal over HTTP can create, delete or modify data and control access settings, leading to full compromise of confidential and integrity‑sensitive portal content.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are components of Oracle Fusion Middleware and are frequently deployed in enterprise portal deployments.
Risk and Exploitability
The CVSS base score of 9.1 indicates a high impact with confidentiality and integrity loss, while the EPSS score of less than 1% suggests that exploitation is currently rare but possible. The attack vector is purely network‑based via HTTP and requires no authentication, meaning any external host with connectivity to the portal can initiate the exploit. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high impact and non‑zero exploitation probability warrants immediate attention.
OpenCVE Enrichment