Executive brief
Oracle WebCenter Portal is a web-based platform for building and managing enterprise portals and collaboration spaces. An unauthenticated remote attacker can exploit this vulnerability over the network to gain complete control of the affected system, compromising confidentiality, integrity, and availability of portal data and services.
Technical details
This is an easily exploitable vulnerability in the Composer component of Oracle WebCenter Portal that allows unauthenticated remote code execution. The vulnerability is reachable via HTTP without authentication or user interaction required. A successful attack results in complete compromise of the WebCenter Portal system, including unauthorized access to all data and the ability to modify or delete content. The vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0; patch information was not accessible from the provided advisory sources.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed