Impact
A flaw in the client bundle component of Oracle WebCenter Enterprise Capture permits a low‑privileged attacker with network access to the T3 and IIOP interfaces to gain unrestricted control over the application. The vulnerability results in full compromise of the system, affecting confidentiality, integrity, and availability. The weakness is an improper access control issue, identified as CWE-284.
Affected Systems
Affected systems include Oracle Corporation’s WebCenter Enterprise Capture, specifically version 12.2.1.4.0 and 14.1.2.0.0. These versions lack the fix for the client bundle flaw.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only network reachability to the T3 or IIOP interfaces and no elevated privileges to exploit the flaw.
OpenCVE Enrichment