Impact
Vulnerability in Oracle WebCenter Enterprise Capture's Client Bundle permits a low‑privileged network attacker to bypass normal authentication controls and hijack the application. Successful exploitation results in full takeover of the WebCenter Enterprise Capture instance, exposing confidential data, modifying or deleting content, and potentially granting the attacker administrative privileges over the underlying system. The weakness is an authorization flaw (CWE‑284) affecting confidentiality, integrity, and availability.
Affected Systems
This issue affects Oracle Corporation's WebCenter Enterprise Capture product. The versions that are known to be vulnerable are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is present in the Client Bundle component of these releases.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 signals high severity. The EPSS score is less than 1%, indicating limited current exploitation activity. The vulnerability is not listed in CISA's KEV catalog. The attack vector is request; a low‑privileged attacker with connectivity to the WebCenter server can trigger the flaw by sending a crafted request, making exploitation relatively straightforward for an adversary within the same network.
OpenCVE Enrichment