Impact
A vulnerability in the Oracle WebCenter Portal product allows a low‑privileged attacker send HTTP requests to gain unauthorized access to critical data, potentially exposing all content managed by the portal. The weakness is an instance of improper access control, which gives the attacker the ability to read sensitive information that should be restricted. This flaw results in a high confidentiality impact while not directly affecting integrity or availability.
Affected Systems
Oracle Corporation’s WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other Oracle products are listed as directly impacted in the advisory.
Risk and Exploitability
The CVSS v3.1 base score is 7.7, indicating a medium‑to‑high severity. The EPSS score of less than 1 % suggests exploitation vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is network‑based via HTTP, requiring only local or remote network connectivity. The vulnerability’s scope change allows an attacker to affect additional products beyond the portal, magnifying its potential impact. Successful exploitation results in confidential data disclosure or complete data access for the affected portal instances.
OpenCVE Enrichment