Impact
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 contain a flaw in Portlet Services that permits an unauthenticated attacker to send SOAP requests and gain full control of the portal. Successful exploitation enables the attacker to read, modify, and delete data and to execute arbitrary commands with the same privileges as the portal, effectively taking over the entire application. The vulnerability is a classic Improper Access Control, as confirmed by its CWE-284 classification, and the lack of authentication checks on SOAP endpoints facilitates the compromise.
Affected Systems
The flaw affects Oracle WebCenter Portal operated by Oracle Corporation. The affected releases are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. Users deploying these versions must verify the installed product release and determine whether their environments are exposed to SOAP traffic from untrusted networks.
Risk and Exploitability
The CVSS v3.1 base score is 9.6, indicating significant confidentiality, integrity and availability impacts, while the EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation at present the CISA KEV catalog. Attackers must send specially crafted SOAP messages over the network; however, successful exploitation requires human interaction from a person an automated attack cannot fully succeed without another person’s involvement. The impact may extend beyond Oracle WebCenter Portal to other connected applications due to the scope change. The combination of a low EPSS and a high CVSS suggests that, although exploitation may not be widespread now, the vulnerability remains a severe threat if active exploitation occurs.
OpenCVE Enrichment