Impact
A flaw in Oracle WebCenter Sites permits an unauthenticated attacker with network access via HTTP to create, delete, or alter critical site data. Because the vulnerability bypasses all access controls, it can compromise the confidentiality and integrity of all data stored in affected instances. The flaw is identified as CWE‑284: Improper Access Control, and the vendor’s advisory notes that successful exploitation would allow an attacker to gain complete or partial data manipulation rights over the entire WebCenter Sites ecosystem.
Affected Systems
Oracle WebCenter Sites, part of Oracle Fusion Middleware, is affected in versions 12.2.1.4.0 and 14.1.2.0.0. No other products or variants were referenced in the advisory, and the scope change note indicates that related components could also be impacted if the flaw is exploited.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 classifies this issue as high severity, reflecting full confidentiality and integrity compromise. The EPSS score of less than 1% suggests that active exploitation is currently unlikely but possible. The vulnerability is remote and requires only unauthenticated HTTP access; no user interaction is needed. The advisory indicates no publicly released exploit, and the flaw is listed as not included in the CISA KEV catalog. However, because the issue can affect multiple products through a scope change, the overall risk to organizations deploying WebCenter Sites remains significant.
OpenCVE Enrichment