Impact
The vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to compromise the application. It is easily exploitable and can lead to full takeover of the site, affecting confidentiality, integrity, and availability as described by the CVSS vector.
Affected Systems
The affected systems are the Oracle WebCenter Sites component of Oracle Fusion Middleware. Versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable.
Risk and Exploitability
The CVSS base score is 10.0, indicating extreme severity. The EPSS score is below 1%, suggesting current exploitation risk is low but could increase. The vulnerability is not listed in the CISA KEV catalog, but its scope change means additional related products could be impacted. The attack can be performed over HTTP and requires no credentials, making it attractive for adversaries seeking complete compromise.
OpenCVE Enrichment