Impact
The vulnerability in Oracle WebCenter Sites is an authentication bypass that allows an unauthenticated attacker to acquire fully authorized privileges. Successful exploitation can result in complete takeover of the WebCenter Sites application, exposing all managed content, configuration data, and potentially the underlying host. The CVSS 3.1 Base Score of 9.8 reflects maximum confidentiality, integrity, and availability impact.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. These releases are part of the Oracle Fusion Middleware suite and are commonly deployed by organizations for web content and collaborative services.
Risk and Exploitability
The CVSS Base Score of 9.8 indicates critical severity. Based on the EPSS score, the probability of exploitation is currently low. The vulnerability is listed as not in the CISA KEV catalog, but it can be exploited over plain HTTP from any external network, requiring only network access and no authentication. This combination of easy exploitation and lack of authentication eases the attack and increases its feasibility.
OpenCVE Enrichment