Executive brief
Oracle WebCenter Portal is a web-based portal and collaboration platform used to build business applications and content management systems within enterprises. A vulnerability in the Composer component allows a low-privileged attacker with network access to gain full administrative control over the portal and potentially compromise connected systems. This could lead to unauthorized access to sensitive business data, disruption of critical portal services, and lateral movement to other enterprise systems.
Technical details
This vulnerability in the Oracle WebCenter Portal Composer component is easily exploitable via HTTP by an attacker with low privilege credentials and network access. The vulnerability results in a scope change, meaning successful exploitation can impact systems beyond the portal itself. An attacker can achieve complete compromise of the WebCenter Portal application, resulting in confidentiality, integrity, and availability impacts. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Patch availability and specific technical remediation details are not confirmed from the provided advisory.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed