Impact
Vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture allows an attacker with low privileges and network access via HTTP to gain control over the application, potentially leading to full takeover. The flaw is high severity, with CVSS v3.1 Base Score 8.8, indicating significant confidentiality, integrity and availability impacts.
Affected Systems
Oracle Corporation’s WebCenter 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS vector indicates Attack Vector Network, Low Access Complexity, and Privileges Required Low, meaning exploitation is likely over the web. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog; however, the high severity and network reach make it a considerable risk if left uncovered.
OpenCVE Enrichment