Impact
The vulnerability is a local access control weakness in the client bundle of Oracle WebCenter Enterprise Capture. It allows a low‑privileged user who has logged on to the infrastructure to alter the behavior of the application, resulting in unauthorized creation, deletion, or modification of critical data. Because the flaw can be leveraged to gain complete access to all data exposed through the product, both confidentiality and integrity are severely impacted. The exploit requires user interaction from a person other than the attacker; therefore it is not remotely exploitable but can be triggered by an attacker who persuades a legitimate user to perform a specific action.
Affected Systems
The affected product is Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, in versions 12.2.1.4.0 and 14.1.2.0.0. The client bundle component is the area affected; no other products have been identified as directly vulnerable, though successful exploitation may impact additional applications that rely on the same data.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates moderate to high severity with high confidentiality and integrity impact. The EPSS score is less than 1 percent, suggesting a very low exploitation probability at present. The vulnerability is not KEV catalog. Because the attack requires local user access and user interaction, the likelihood of widespread attacks is constrained, but the scope change shows that a successful compromise could undermine data integrity across the webcenter environment.
OpenCVE Enrichment