Impact
The vulnerability in Oracle WebCenter Sites allows an attacker with low privileges and network access via HTTP to compromise the system, potentially taking full control. It exposes confidentiality, integrity, and availability by enabling a complete takeover of the application.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. This product is part of Oracle Fusion Middleware and is used by organizations that host web‑facing content.
Risk and Exploitability
The CVSS 3.1 base score is 7.5, indicating a high severity. EPSS is below 1%, implying a very low current exploitation probability. The vulnerability is not listed in CISA KEV. Attackers would need to send a crafted HTTP request from a low‑privileged account; no elevated privileges are required. If exploited, the attacker can take over the entire application, affecting all users and data.
OpenCVE Enrichment