Impact
The vulnerability is a broken access control flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture. access over HTTP and high privileges can exploit the flaw, but the attack requires human interaction from another individual. It may allow creation, deletion, or alteration of critical data, and unauthorized access to all data exposed by the application. The impact is on confidentiality and integrity; availability is not affected.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware, are affected. The vulnerability resides in the client bundle component, and due to scope change, other Oracle products may also be impacted.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, while the EPSS score is less than 1%, suggesting a low current exploitation probability. The vulnerability is listed as a broken access control flaw that can be exploited via a remote HTTP request with low attack complexity. It is not listed in the CISA KEV catalog. The attack requires the attacker to have high privileges and to convince another user to interact with the malicious payload. Successful exploitation can allow creation, deletion, or modification of critical data and unauthorized access to all data exposed by the application.
OpenCVE Enrichment