Impact
This vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation grants unauthorized access to critical data or full access to all site data, representing a high confidentiality impact. The weakness can be classified as an improper access control issue, allowing information disclosure without proper authorization. CVSS 3.1 score is 7.5 with AV:N, AC:L, PR:N, UI:N, S:U, C:H, I:N, A:N.
Affected Systems
The affected product is Oracle WebCenter Sites, part of Oracle Fusion Middleware, version 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The severity is moderate to high with a CVSS base score of 7.5. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is via HTTP to an unauthenticated user; the attacker does not need any credentials or privileged access. Given the network exposure, the exploitation risk is significant for organizations operating the vulnerable instances.
OpenCVE Enrichment