Impact
The vulnerability in Oracle WebCenter Sites permits an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation requires the involvement of an unrelated user to provide input, after which the attacker can gain unauthorized access to critical data or complete control over all data accessible through the site. The flaw results in a confidentiality breach but does not impact integrity or availability.
Affected Systems
Affected are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, both part of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 reflects a medium severity vulnerability with a high confidentiality impact. The EPSS score indicates less than 1 % probability that it will be exploited in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network via HTTP and necessitates human interaction from a person other than the attacker, which reduces the likelihood of automated exploitation but still presents a risk to organizations that expose WebCenter Sites to the Internet.
OpenCVE Enrichment