Executive brief
Oracle WebCenter Portal is a content management and collaboration platform used within Oracle Fusion Middleware deployments. An attacker with physical or adjacent network access to the hardware running WebCenter Portal can compromise the system without authentication, potentially gaining complete control over the portal and its data. This vulnerability is difficult to exploit as it requires direct access to the same network segment, but successful exploitation could result in a full takeover of the system.
Technical details
This is a difficult-to-exploit vulnerability in Oracle WebCenter Portal (version 14.1.2.0.0) that allows an unauthenticated attacker with adjacent network access to compromise the application. The vulnerability resides in the Runtime Tools component and requires direct access to the physical communication segment attached to the hardware. While authentication is not required, successful exploitation grants complete takeover capability, affecting confidentiality, integrity, and availability. Patches and mitigations are expected from Oracle's security advisory.
Affected products
- Oracle WebCenter Portal 14.1.2.0.0
Timeline
- 2026-09-15: disclosed