Impact
Oracle WebCenter Portal’s Runtime Tools component has a vulnerability that allows a high‑privileged attacker with network access via HTTP to compromise the portal. The flaw can result in full takeover of the WebCenter Portal application, impacting confidentiality, integrity, and availability. The CVSS 3.1 vector indicates that the attack requires an attacker who already has high privileges on the target and is able to invoke the flaw over a network connection without user interaction.
Affected Systems
The affected products are Oracle WebCenter Portal version 12.2.1.4.0 and version 14.1.2.0.0. The vulnerability is documented by Oracle and the official advisory lists these two specific releases as impacted.
Risk and Exploitability
The CVSS base score of 9.1 marks the vulnerability as critical, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. It is not currently listed in the CISA KEV catalog. Based on the vector (AV:N/AC:L/PR:H), the attack requires an attacker with high privileges and a network path to the WebCenter Portal, likely via an exposed HTTP endpoint. Successful exploitation would give the attacker full control of the portal, potentially affecting other products that rely on it due to a scope change.
OpenCVE Enrichment