Impact
The vulnerability is a flaw in the Runtime Tools component of Oracle WebCenter Portal that allows an unauthenticated attacker to access critical data or all accessible Portal data. This weakness is an authorization bypass, described as CWE‑284. The attacker need only send a crafted request over the network. Successful exploitation compromises confidentiality by exposing insecure data and can also provide full control over Portal resources.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are installed in many enterprise environments.
Risk and Exploitability
The CVSS 3.1 base score is 7.5, indicating a high risk to confidentiality. The EPSS score is < 1 %, suggesting exploitation is unlikely in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based HTTP traffic to the Portal. If exploited, an attacker can read confidential data and potentially gain complete data access without authentication.
OpenCVE Enrichment