Executive brief
Oracle WebCenter Enterprise Capture is a document management and processing system used to capture and manage business documents within Oracle Fusion Middleware. A low-privilege attacker with network access can exploit this vulnerability to gain complete control over the system, potentially exposing or modifying sensitive business documents and disrupting document processing operations.
Technical details
This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and requires only network access and low-privilege credentials, with no user interaction needed. An authenticated attacker can send specially crafted HTTP requests to achieve complete system compromise with impact to confidentiality, integrity, and availability. Patch information is not available in the provided advisory; contact Oracle for remediation details.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed