Impact
The vulnerability is in the Runtime Tools component of Oracle WebCenter Portal and allows an unauthenticated attacker with network access via HTTP to read privileged data and perform update or delete operations. The flaw permits an attacker to bypass authentication and access all data exposed by the portal, leading to confidentiality and integrity compromise of sensitive information within the portal application.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is specific to those releases of the Oracle Fusion Middleware WebCenter Portal product.
Risk and Exploitability
The CVSS base score of 8.2 reflects a high severity, though the EPSS score is below 1%, indicating low current exploit activity, and the flaw is not listed in the CISA KEV catalog. Because the attack requires only unauthenticated HTTP access, the attacker can perform the vulnerability exploitation remotely from any network-connected system with visibility to the portal port. Once exploited, the attacker can read confidential data or alter records without legitimate credentials.
OpenCVE Enrichment