Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive business data, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. A successful exploit results in a 'scope change' (S:C), meaning the attacker can impact components beyond the immediate security scope of the application, potentially leading to a total takeover of the host. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory