Impact
The flaw in Oracle WebCenter Sites allows any unauthenticated attacker with network access through HTTP to send crafted requests that result in a full takeover of the application. This enables the attacker to exfiltrate data, modify content, and disrupt services, compromising the confidentiality, integrity, and availability of the affected instance.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. No other supported releases are listed as affected.
Risk and Exploitability
The assignment earned a CVSS v3.1 score of 9.8, categorising it as critical. The EPSS score of less than 1% indicates a low but non‑zero exploitation probability. The vulnerability is not in the CISA KEV catalog. Attackers can exploit it over the network via HTTP without authentication, making it remotely exploitable and easily usable for takeover.
OpenCVE Enrichment