Impact
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 contain an authentication bypass flaw (CWE‑284) that allows an unauthenticated attacker to send HTTP requests that create, delete or modify critical data. The exploit grants complete control over all data accessible through WebCenter Sites, causing confidentiality and integrity loss for all stored information.
Affected Systems
Oracle WebCenter Sites, part of Oracle Fusion Middleware, is affected for the release series 12.2.1.4.0 and 14.1.2.0.0. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 9.1 classifies this as a high‑severity vulnerability, with severe confidentiality and integrity impacts. The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not included in the CISA KEV catalog. Nonetheless, because the flaw can be exploited remotely over HTTP without authentication or user interaction, an attacker who reaches the affected instance could immediately manipulate or delete data, making the risk significant for environments that expose WebCenter Sites to the internet.
OpenCVE Enrichment