Impact
A low-privilege attacker with network access can exploit a flaw in the Client Bundle of Oracle WebCenter Enterprise Capture. The vulnerability arises from improper access control (CWE-284) and allows the attacker to read critical data or perform unauthorized update, insert, or delete operations, thereby compromising confidentiality and integrity.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and may interact with other Oracle products, potentially expanding the attack surface.
Risk and Exploitability
The CVSS v3.1 score of 8.5 indicates a high severity with significant confidentiality impact. The EPSS score is less than 1 %, suggesting low predicted exploitation likelihood currently. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is SOAP over the network, and a low‑privileged attacker can leverage it to gain unauthorized access to sensitive data and modify data records. Proper access controls are essential to mitigate this risk.
OpenCVE Enrichment