Impact
A flaw in the Runtime Tools component of Oracle WebCenter Portal allows an unauthenticated attacker who has physical or local access to the server to bypass authentication and take over classified as CWE‑284 (Improper Access Control) and also aligning with CWE‑285 (Improper Authorization), leads to loss of confidentiality, integrity, and availability for the portal, granting the attacker full control of the system. The attack requires an attacker to be present on the same physical network segment as the hardware running the portal, which is inferred from the description that the “unauthenticated attacker with access to the physical communication segment” can exploit the flaw.
Affected Systems
Oracle WebCenter Portal, version 14.1.2.0.0. This is the sole version identified by the CNA as affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% points to a low likelihood of exploitation in the wild, although the risk is elevated once an attacker gains the necessary physical or local access. The flaw is not listed in the CISA KEV catalog, so it is not known to be actively exploited at scale. Because the exploitation local access, the potential impact is limited to environments where physical or local host compromise is possible, but any successful attack results in total takeover of the portal.
OpenCVE Enrichment