Impact
A vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to compromise the application, potentially granting unauthorized access to critical or all data accessible through the site. The CVSS 3.1 base score of 8.6 reflects a high confidentiality impact with no impact on integrity or availability, while the attack vector is network-based and requires no user interaction.
Affected Systems
The affected product is Oracle WebCenter Sites, specifically versions 12.2.1.4.0 and 14.1.2.0.0, as identified by Oracle Corporation under the Oracle Fusion Middleware umbrella.
Risk and Exploitability
The risk score is 8.6, but the EPSS score is below 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker sending crafted HTTP requests to the vulnerable WebCenter Sites instance from any externally reachable host, bypassing authentication and enabling data disclosure. Because the vulnerability changes the scope for additional products, an exploiter could potentially impact other Oracle Fusion Middleware components if misconfigured.
OpenCVE Enrichment