Impact
The vulnerability in the Oracle WebCenter Portal relies on improper access control allowing a low‑privileged user with HTTP network access to read and manipulate portal data. Successful exploitation can expose critical data and enable unauthorized updates, inserts, or deletions. The weakness is classified as CWE‑284. The CVSS 3.1 score of 7.1 reflects a high confidentiality impact and a moderate integrity impact.
Affected Systems
Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions were released as part of Oracle Fusion Middleware and remain supported by Oracle.
Risk and Exploitability
The exploit is relatively easy to perform over the network; an attacker needs only low privilege access and the ability to send HTTP requests to the portal. The EPSS value of < 1% suggests that public exploits have not yet been observed, but the CVSS score indicates a serious potential consequence if the vulnerability is hit. The vulnerability is not currently listed in the CISA KEV catalog. Administrators should consider the risk high enough to address promptly but can prioritize according to their threat model and exposure.
OpenCVE Enrichment