Impact
The vulnerability is an improper access‑control flaw that allows an attacker with low privileges and network access via HTTP to read critical data and gain broad access to all data available through the WebCenter Portal. Successful exploitation can also induce a partial denial of service. The weakness is categorized as CWE-284. The impact is a loss of confidentiality and a degradation of availability, as described by the CVSS vector.
Affected Systems
Vendor Oracle delivers the affected product WebCenter Portal. The versions impacted are 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a high‑medium severity. The EPSS score of less than 1% implies a low probability of exploitation in the current environment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based HTTP, requiring only low privileges to achieve impact.
OpenCVE Enrichment