Impact
The flaw resides in the Runtime Tools component of Oracle WebCenter Portal and allows a low‑privileged attacker with network access over HTTP to gain unauthorized read and, in some cases, modify or delete data. The vulnerability directly affects confidentiality and, to a lesser extent, integrity, as reflected by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N. It therefore permits attackers to exfiltrate or alter portal data without authentication, elevating their privileges beyond ordinary users.
Affected Systems
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and provide web‑based portal services used by many enterprises.
Risk and Exploitability
The base score of 8.5 classifies the issue as high severity, and the EPSS score of less than 1% indicates a low but not negligible likelihood of exploitation. The vulnerability is listed as Not in KEV, so no active exploits have been documented yet. Nonetheless, the attack vector is remote (HTTP) and requires only network access, making it exploitable by attackers with minimal privileges. The scope change noted in the description means that compromise of the portal could potentially impact other products within the same environment.
OpenCVE Enrichment