Impact
A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows an attacker with low privileges but network access via HTTP to compromise the portal. Exploitation can lead to the attacker obtaining full control, resulting in a complete takeover of the portal. The CVSS vector reflects high impacts on confidentiality, integrity and availability, indicating that compromise can affect all core services and data.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected – any installation of these releases is vulnerable if the Runtime Tools component is enabled.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity. The EPSS score is less than 1 %, suggesting low immediate exploitation likelihood, but the existence of an HTTP‑exposed interface and the low privilege requirement means an attacker can reach the target from any connected network. This vulnerability is not listed in CISA’s KEV catalog, yet the impact of a successful exploit is significant, so the overall risk remains high for exposed or inadequately segmented environments.
OpenCVE Enrichment