Impact
This vulnerability in Oracle WebCenter Sites 14.1.2.0.0 allows an unauthenticated attacker who can reach the appliance over HTTP to take full control of the site. The flaw creates a complete compromise, exposing all data, enabling modification or deletion, and potentially allowing the attacker to pivot to other systems.
Affected Systems
The only affected product is Oracle WebCenter Sites version 14.1.2.0.0 as specified in the vendor advisory. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS v3.1 score of 9.8 combined with an EPSS score of less than 1% indicates a critical severity but a low probability of exploitation in the current landscape. The vulnerability is not in the CISA KEV catalogue. Attackers can exploit it over the public internet using a simple HTTP request, without authentication, to gain full control of the application and its underlying data. Because it is network‑based and unauthenticated, exposed sites face a high risk of takeover.
OpenCVE Enrichment