Impact
A flaw in the Runtime Tools component of Oracle WebCenter Portal allows an unauthenticated attacker who has physical or local access to the server to bypass authentication and take over classified as CWE‑284 (Improper Access Control), leading to loss of confidentiality, integrity, and availability for the portal and granting the attacker full control of the system.
Affected Systems
Oracle WebCenter Portal, version 14.1.2.0.0. This is the sole version identified by the CNA as affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1 % points to a low likelihood of exploitation in the wild, although the risk is elevated once an attacker gains the necessary physical or local access. The flaw is not listed in the CISA KEV catalog, so it is not known to be actively exploited at scale. Because the exploitation requires local or physical access, the potential impact is limited to environments where such access is possible, but any successful attack results in total takeover of the portal.
OpenCVE Enrichment