Impact
The vulnerability in Oracle WebCenter Enterprise Capture’s Client Bundle allows an attacker with low privileges who can reach the service over HTTP to compromise the application. Once exploited, the attacker can read critical data, and can also modify or delete data that the application exposes. The weakness is a low-privileged attacker with network reach via HTTP, enabling unauthorized read and write operations. The impact, as defined by the CVSS vector, shows severe confidentiality loss with moderate integrity damage and no availability impact.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The product belongs to Oracle Fusion Middleware and is deployed in environments that expose the Client Bundle to HTTP traffic. No other product versions are disclosed as vulnerable in the current advisory.
Risk and Exploitability
The CVSS score of 8.5 places this issue in the high-severity range. Although the EPSS score is below 1%, indicating a low overall likelihood of public exploitation, the CVE is not listed in the KEV catalog. The flaw does not require authentication beyond user credentials presented over HTTP, making it easy to exploit once network access is available. Because the scope changes, successful exploitation could also impact other products that rely on or integrate with the compromised Enterprise Capture component.
OpenCVE Enrichment