Impact
A vulnerability in Oracle WebCenter Sites allows a low‑privilege attacker who can reach the exposed HTTP interface to compromise the application. Successful exploitation requires a user other than the attacker to interact with the vulnerable content; when triggered the flaw can lead to a complete takeover of the WebCenter Sites instance, impacting confidentiality, integrity and availability. The weakness manifests as an improper privilege escalation that permits an attacker to execute privileged actions after luring a target user into a specific interaction.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are part of Oracle Fusion Middleware and deployable on various operating systems where the WebCenter Sites engine runs.
Risk and Exploitability
The CVSS base score of 8.0 highlights high severity, with high impacts on confidentiality, integrity and availability. The EPSS score of less than 1% indicates that while exploitation is currently uncommon, the vulnerability remains exploitable. The flaw is not listed in the CISA KEV catalog. Attackers would likely use the public HTTP interface to deliver a malicious payload that a secondary user must activate, exploiting low attack complexity and low privilege requirements. A successful attack grants the attacker full control over the application, enabling data theft, tampering, or denial of service.
OpenCVE Enrichment