Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing large volumes of business documents, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the network without needing a username or password. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) is classified as a missing authentication flaw (CWE-306). The issue is easily exploitable by an unauthenticated attacker with network access via Remote Method Invocation (RMI). Successful exploitation allows for a complete takeover of the application, impacting confidentiality, integrity, and availability. Due to a scope change (S:C), an attack on this component may also significantly impact additional products beyond WebCenter Enterprise Capture itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published