Impact
This vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to exploit an improper access control weakness (CWE‑284) and gain unauthorized access to critical data or full site data. Successful exploitation results in a high confidentiality impact while integrity and availability are not affected. The weakness permits information disclosure without proper authorization.
Affected Systems
The affected product is Oracle WebCenter Sites, part of Oracle Fusion Middleware, with vulnerable versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The severity is moderate to high, reflected by a CVSS base score of 7.5 with an AV:N, AC:L, PR:N, UI:N, S:U, C:H, I:N, A:N vector. The EPSS score is below 1%, indicating a low but non‑zero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is via HTTP to an unauthenticated user, requiring no credentials, which means organizations exposed to public or untrusted networks face a significant risk of data compromise.
OpenCVE Enrichment