Executive brief
Oracle WebCenter Portal is an enterprise portal and content management platform used to build collaborative workspaces and web applications. An unauthenticated attacker can exploit this vulnerability over the network to read, modify, or delete sensitive data stored in the portal, requiring only that a legitimate user interact with a malicious link or content. The vulnerability has a wide scope of impact, potentially affecting other connected systems and applications.
Technical details
This is an easily exploitable vulnerability in the Portlet Services component of Oracle WebCenter Portal that allows unauthenticated network access via HTTP. The attack requires user interaction (UI:R) and results in scope change (S:C), indicating that the vulnerability in WebCenter Portal can impact security boundaries of other systems. The vulnerability permits unauthorized creation, deletion, modification, and read access to critical data. While the exact vulnerability class is not specified in the advisory, the combination of unauthenticated network access, user interaction requirement, and data manipulation capabilities suggests either a cross-site scripting (XSS) or authentication bypass flaw. Oracle has released patches for affected versions 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed