Impact
The vulnerability resides in the Composer component of Oracle WebCenter Portal. It allows a low‑privileged attacker who has network access through HTTP to compromise the portal. Successful exploitation can lead to a full takeover of the WebCenter Portal, affecting confidentiality, integrity, and availability. The weakness is an unauthorized access-284.
Affected Systems
This issue affects Oracle Corporation’s WebCenter Portal product, specifically versions 12.2.1.4.0 and 14.1.2.0.0. Only these releases are known to be vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.8 marks the vulnerability as high severity, and the EPSS score of less than 1% indicates a low exploitation probability at present. The vulnerability is listed as not part of the CISA KEV catalog. It is exploitable via an unauthenticated HTTP request from a network‑attached attacker, making it potentially easy to leverage if the target is open to the Internet or an internal network.
OpenCVE Enrichment