Impact
The flaw resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and enables a low‑privileged attacker with network access through HTTP to execute arbitrary actions that result in a full takeover of the application. Successful exploitation removes confidentiality, integrity, and availability protections, giving the attacker control over the system.
Affected Systems
Oracle Corporation’s Oracle WebCenter Enterprise Capture product is impacted. The affected releases are 12.2.1.4.0 and 14.1.2.0.0, which are commonly deployed within Oracle Fusion Middleware environments.
Risk and Exploitability
The base CVSS score of 8.8 classifies this vulnerability as high severity with network access, low attack complexity, low privileges, and no user interaction required. The EPSS score of less than 1% indicates a low probability of exploitation at the the CISA KEV catalog. Because the attack can be carried out by an attacker who only needs HTTP access and does not require elevated credentials, the potential impact is substantial if the affected environment is exposed to untrusted networks.
OpenCVE Enrichment