Impact
A flaw in the Client Bundle of Oracle WebCenter Enterprise Capture permits an unauthenticated attacker who can reach the physical network segment attached to the hardware hosting the software to compromise the system. The vulnerability requires user interaction from a third party and has an attack complexity rated high. If exploited, it could lead to full takeover of the WebCenter Enterprise Capture application, compromising confidentiality, integrity and availability as reflected by a CVSS 3.1 score of 7.9.
Affected Systems
Oracle WebCenter Enterprise Capture products shipped as versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue is confined to the Client Bundle component of the Fusion Middleware stack.
Risk and Exploitability
The CVSS base score of 7.9 indicates a high level of risk, while the EPSS score of less than 1% suggests that attacks are infrequent but still possible. The vulnerability is not listed in the CISA KEV catalog, yet its scope change property means that compromise of the WebCenter application could extend to other components in the Fusion Middleware environment. Exploitation requires physical network access and a human who can interact with the target, reducing the likelihood of automated attacks but still presenting a significant threat to environments where such access is possible.
OpenCVE Enrichment