Impact
Oracle WebCenter Enterprise Capture contains an easily exploitable weakness in its client bundle that allows an attacker who has only low privileges and network access via HTTP to compromise the system. Because the flaw bypasses normal access controls, compromised data can be read and, in some cases, the attacker may gain full read access to all data available through the application. The vulnerability is tied to Improper Access Control (CWE‑284) and results in a high confidentiality impact (CWE‑200).
Affected Systems
The flaw affects Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0. The impact may extend beyond these specific installations, potentially affecting other Oracle Fusion Middleware components that rely on the same client bundle.
Risk and Exploitability
With a CVSS v3.1 base score of 7.7, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that real‑world exploitation is currently unlikely, and the issue is not listed in CISA KEV. Nonetheless, an attacker can exploit the flaw remotely over HTTP without user interaction (no UI required) and requires only low privileges. The risk is compounded by the fact that successful exploitation can lead to confidentiality breaches that might cascade into other product instances.
OpenCVE Enrichment