Impact
The vulnerability in Oracle WebCenter Portal’s Portlet Services allows an unauthenticated attacker with network access over HTTP to compromise the portal, which can lead to full takeover. The flaw is an improper authentication (CWE‑287) combined with missing authentication for privileged functions (CWE‑306). Successful exploitation results in complete loss of confidentiality, integrity, and availability, as indicated by the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
Affected systems are Oracle WebCenter Portal installations running the following versions: 12.2.1.4.0 and 14.1.2.0.0. The issue targets the Portlet Services component within the Oracle Fusion Middleware suite and does not affect earlier or later major releases beyond these specific builds.
Risk and Exploitability
Risk assessment shows a CVSS base score of 9.8, indicating critical severity. The EPSS score is less than 1%, suggesting that widespread exploitation is not yet observed, and the vulnerability has not been listed in CISA’s KEV catalog. Nevertheless, because the attack requires only an unauthenticated HTTP connection, it remains easily exploitable in open or poorly secured environments. An attacker could send a crafted request to the exposed endpoint to bypass authentication and gain unrestricted control over the portal application, including data disclosure, modification, and service disruption.
OpenCVE Enrichment