Impact
The vulnerability resides in the Runtime Tools component of Oracle WebCenter Portal and represents an improper access control (CWE-284) weakness, allowing an unauthenticated attacker with network access via HTTP to read privileged data and execute update or delete operations. This flaw bypasses authentication mechanisms and grants full access to all portal data, resulting in confidentiality and integrity compromise of sensitive information.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is specific to those releases of the Oracle Fusion Middleware WebCenter Portal product.
Risk and Exploitability
The CVSS base score of 8.2 reflects a high severity, though the EPSS score is below 1%, indicating low current exploit activity, and the flaw is not listed in the CISA KEV catalog. Because the attack requires only unauthenticated HTTP access, the attacker can perform the vulnerability exploitation remotely from any network-connected system with visibility to the portal port. Once exploited, the attacker can read confidential data or alter records without legitimate credentials.
OpenCVE Enrichment