Impact
A flaw in the Composer component of Oracle WebCenter Portal allows a low‑privileged attacker who can reach the application over HTTP to bypass access controls and fully compromise the portal. The vulnerability, identified as an improper access control weakness (CWE‑284), can result in the attacker gaining full control of the portal, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability impacts only these product builds, but the scope change in the CVSS vector indicates that related Oracle Fusion Middleware components that integrate with the portal could also be affected if the compromise extends beyond the portal.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.9 signals a critical risk, while the EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack requires only network access to the portal’s HTTP interface; therefore, it is easily reachable for attackers who can reach the Portal from the same network or over the Internet, making it a practical risk for exposed deployments.
OpenCVE Enrichment