Impact
A vulnerability in Oracle WebCenter Sites allows an attacker who is unauthenticated and has network access to the HTTP interface to fully compromise the system. The flaw can be exploited without any prior user credentials and results in a complete takeover, granting the attacker full control over the application, which results in loss of confidentiality, integrity, and availability. The vendor has assigned a CVSS v3.1 score of 9.8, indicating a severe impact with all three core security properties affected.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The vulnerability is actively exploitable from the network because it is triggered by unauthenticated HTTP requests. The EPSS score is less than 1 %, which indicates a very low current probability of real‑world exploitation, yet the high CVSS base of 9.8 and the lack of a CISA KEV listing mean that once an attacker identifies the target, successful compromise is highly likely. Exploitation requires only standard HTTP traffic, so no special tools are needed beyond a web client.
OpenCVE Enrichment