Impact
The vulnerability in Oracle WebCenter Portal allows low‑privileged attackers with network access via HTTP to obtain unauthorized access to critical data and to insert, update, or delete portal data. This weakness is classified as CWE‑284. The CVSS 3.1 score of 7.1 indicates a high confidentiality impact and a low integrity impact.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Both versions are part of Oracle Fusion Middleware.
Risk and Exploitability
The vulnerability is easily exploitable over HTTP by a low‑privileged user. An attacker only requires network access with HTTP capability. The EPSS score is less than 1%, indicating few or no public exploits have been observed. The CVSS score of 7.1 indicates a high confidentiality impact and a low integrity impact. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment