Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability in its Client Bundle component. A low-privileged user can exploit this flaw over a network to take full control of the system. This could lead to the theft of sensitive business data, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. Successful exploitation results in a 'scope change' (S:C), meaning the attacker can move beyond the affected component to impact other parts of the environment. This can lead to a total takeover of the application, compromising confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published the security alert.