Impact
A flaw in Oracle WebCenter Sites allows attackers who can reach the application over HTTP to gain access without authentication. The vulnerability, categorized as CWE‑200, enables an unauthenticated actor to read protected data or, in the worst case, all content stored in the application, thereby compromising confidentiality.
Affected Systems
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 are affected. Because the flaw changes the security scope, other components in the same environment could be impacted by a successful exploitation.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 highlights serious confidentiality damage, while the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation can be achieved from any network that can reach the HTTP interface, requiring no credentials or user interaction.
OpenCVE Enrichment