Impact
A flaw in Oracle WebCenter Portal’s Portlet Services component allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability results in complete takeover of the portal, exposing the confidentiality, integrity, and availability of all data and services hosted by the application. The CVSS v3.1 base score of 9.8 indicates a critical threat with high impact on all CIA triad aspects.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are widely deployed in enterprise web portal environments.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is currently rare, yet the CVSS score of 9.8 highlights the severity if exploited. The vulnerability is reachable over the network via HTTP, meaning any external host could potentially trigger the malicious code in the absence of network segmentation or robust authentication. Although it is not listed in the CISA KEV catalog, the potential for unauthorized use of the portal justifies immediate remediation.
OpenCVE Enrichment