Impact
Oracle WebCenter Content, the Content Server component of Oracle Fusion Middleware, contains a flaw that allows an attacker with a low‑privileged account that has logon access to the same infrastructure to compromise the content server and ultimately take over the application. Successful exploitation results in complete loss of confidentiality, integrity, and availability of the entire WebCenter Content installation.
Affected Systems
The affected products are Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, released by Oracle Corporation.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 7.8 with an attack vector of local, a low attack complexity, low privileges, and no user interaction. The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because it requires only local access and low privileges, an attacker who can log on to the host can quickly achieve full control of the application.
OpenCVE Enrichment