Impact
The flaw is an access‑control weakness in the Portlet Services component of Oracle WebCenter Portal, allowing an unauthenticated attacker to create, delete, or modify data when they successfully interact with an HTTP endpoint. The vulnerability can lead to loss of confidentiality and integrity of critical data, and can be leveraged to obtain full access to all portal data. The weakness is characterized by CWE‑284, an incorrect implementation of access restrictions.
Affected Systems
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 are affected. Any installation of these versions that exposes the HTTP port to external networks is at risk; the impact may extend to other Oracle Fusion Middleware components that rely on the same Portal services.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 reflects a high severity with significant confidentiality and integrity impact. The EPSS score indicates a very low but non‑zero probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need network access to the exposed HTTP port and human interaction to trigger the flaw, but the requirement for direct interaction does not reduce the risk of a successful compromise for a motivated actor.
OpenCVE Enrichment