Executive brief
Oracle WebCenter Portal is an enterprise portal framework used to build and manage web applications within Oracle Fusion Middleware. A vulnerability in its Portlet Services component allows an authenticated attacker with low-level access to gain complete control over the portal system. Successful exploitation could result in takeover of the entire portal platform, compromising confidentiality, integrity, and availability of business-critical applications and data.
Technical details
This vulnerability in Oracle WebCenter Portal's Portlet Services component is easily exploitable by a low-privileged attacker with network access via HTTP. The attack requires authentication (PR:L) but no user interaction (UI:N), and does not require special network conditions (AC:L). A successful exploit grants full control over Oracle WebCenter Portal, affecting confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, and patches should be available through Oracle's security advisory process.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed