Impact
A vulnerability in the Oracle WebCenter Portal Composer component allows an attacker who can reach the application over HTTP to bypass authentication requirements (CWE‑287 and CWE‑306). The flaw is easily exploitable because no credentials are needed, and exploitation results in full takeover of the portal, compromising confidentiality, integrity, and availability as indicated by the CVSS 3.1 score of 9.8.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw resides in the Composer component of the Fusion Middleware stack.
Risk and Exploitability
Although the EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, the high CVSS score and the ability to be exploited without authentication make this flaw a high‑risk surface. An unauthenticated attacker can gain full control simply by sending a malicious HTTP request, with no additional access or privileged context required.
OpenCVE Enrichment