Impact
Oracle WebCenter Portal is vulnerable to an access‑control flaw that can be exploited through a simple HTTP request from a low‑privileged attacker. The flaw, located in the Security Framework component, permits the attacker to read or modify protected data, potentially compromising all Portal data and impacting downstream applications.
Affected Systems
Affected vendors include Oracle Corporation with Oracle WebCenter Portal. Versions 12.2.1.4.0 and 14.1.2.0.0 are impacted; any downstream or integrated applications relying on the Portal may also be affected.
Risk and Exploitability
The CVSS score of 8.5 indicates moderate to high severity with significant confidentiality impact. The EPSS value of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the likely attack vector is a network‑based HTTP exploitation that can lead to unauthorized data access and manipulation; the scope change indicates compromised.
OpenCVE Enrichment