Impact
The flaw resides in the Client Bundle of Oracle WebCenter Enterprise Capture and permits an unauthenticated attacker to gain complete control over the application. This results in total confidentiality, integrity, and availability loss, effectively enabling a full takeover. The weakness involves improper authentication checks, reflected in the CWE identifiers association.
Affected Systems
Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 are impacted. These versions are part of the Oracle Fusion Middleware suite and normally handle media capture and storage services.
Risk and Exploitability
The CVSS 3.1 score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates a low but non‑zero exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. With network access via HTTP and no authentication required, the attack vector is straightforward, allowing remote actors to exploit the flaw without any credential.
OpenCVE Enrichment