Impact
Vulnerability in Oracle WebCenter Sites permits an unauthenticated attacker who can reach the system over HTTP to access critical or all data available through the application. The flaw allows reading sensitive information without valid credentials, reflecting weaknesses in authentication and authorization checks (CWE-200 and CWE-284).
Affected Systems
The affected product is Oracle WebCenter Sites, specifically versions 12.2.1.4.0 and 14.1.2.0.0, as identified by Oracle Corporation under the Oracle Fusion Middleware umbrella.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates a high confidentiality impact. The EPSS score is less than 1%, suggesting a low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker sending crafted HTTP requests from any externally reachable host to bypass authentication and access sensitive data. The description notes that the scope change could allow an attacker to impact additional Oracle Fusion Middleware components if misconfigured.
OpenCVE Enrichment