A vulnerability has been identified in Oracle Document Capture, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a design error in the "blackicedevmode.ocx" ActiveX control when processing arguments supplied via the "SetApplicationPath()" and "SetCustomStartAppParameter()" methods, which could be exploited to inject arbitrary commands by tricking a user into visiting a malicious web page.