Impact
A flaw in Oracle WebCenter Portal allows a high‑privileged attacker with HTTP network access to read, insert, update or delete data available through the portal. The vulnerability leads to a confidentiality impact that is considered high and an integrity impact considered low, as reflected in the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N. The issue is an Improper Access Control weakness (CWE-284).
Affected Systems
Oracle WebCenter Portal, versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability may cause a scope change that can impact other Oracle WebCenter products that rely on the same configuration or authentication mechanisms, as stated explicitly in the advisory.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity attack that severely compromises confidentiality. The EPSS score is below 1%, suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The description explicitly requires the attacker to have high‑privileged credentials and to reach the portal over HTTP in order to exploit the access control flaw. If those conditions are met, the attacker can maintain access to all data exposed through the portal and potentially affect additional products due to the described scope change.
OpenCVE Enrichment