Impact
The vulnerability is an improper authorization bypass that allows an unauthenticated attacker who can reach Oracle WebCenter Sites over HTTP to fully compromise the system. Successful exploitation can result in takeover of the application, enabling the attacker to alter or delete data, execute arbitrary code, and disrupt availability, thereby causing complete loss of confidentiality, integrity, and availability. The weakness corresponds to CWE‑284.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. All deployments of these versions are at risk unless a patch is applied or a newer, non‑affected release is installed.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 marks the vulnerability as critical. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the application, and the impact scope covers the entire WebCenter Sites instance.
OpenCVE Enrichment