Impact
A vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with HTTP network access to compromise the application and obtain unauthorized access to critical data. The flaw permits the attacker to view all data that is normally protected by the application's confidentiality controls. The CVSS 3.1 base score of 7.5 reflects a high confidentiality impact with no requirement for privileges, user interaction, or elevated privileges, and an unmodified scope.
Affected Systems
The issue affects Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0. Administrators of these releases should verify that their deployments include the relevant patch set.
Risk and Exploitability
The EPSS score of less than 1% indicates that the exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of privilege or user interaction requirements means that any system exposed to network traffic that can reach the WebCenter Sites HTTP endpoint is potentially vulnerable. Attackers could exploit the flaw to read sensitive content, but the impact is limited to confidentiality and does not affect integrity or availability.
OpenCVE Enrichment