Impact
Oracle WebCenter Sites has a vulnerability that allows an attacker with low privileges and network access via HTTP to take control of the application. The flaw is easily exploitable and, if successfully leveraged, permits complete compromise of the site, impacting confidentiality, integrity, and availability. With a CVSS vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, the issue is classified as critical.
Affected Systems
The affected versions are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0. As the vulnerability includes a scope change, other products in the Fusion Middleware stack could also be impacted under certain conditions.
Risk and Exploitability
The CVSS base score of 9.9, combined with a low exploitation effort from a low‑privileged attacker, results in a high risk. The EPSS score of <1 % indicates rare current exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. Nonetheless, an attacker with network connectivity can immediately exploit the flaw through standard HTTP traffic, elevating privileges and enabling full takeover of the affected sites.
OpenCVE Enrichment