Impact
The vulnerability exists in Oracle WebCenter Sites (versions 12.2.1.4.0 and 14.1.2.0.0) and allows an attacker who does not need to authenticate, but can reach the system over HTTP, to create, delete or modify data or otherwise gain unauthorized access to all data available through WebCenter Sites. This leads to complete confidentiality and integrity compromise for the affected data. The attack vector is a simple network request over unsecured HTTP and no user interaction beyond sending the request is required.
Affected Systems
Oracle WebCenter Sites, part of Oracle Fusion Middleware, is affected for the release series 12.2.1.4.0 and 14.1.2.0.0. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.1 classifies this as a high‑severity issue with both confidentiality and integrity impacts. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited by an unauthenticated remote attacker and requires only basic HTTP knowledge, the likelihood of exploitation is considered high. Attackers can achieve unrestricted data modification or deletion by sending specially crafted requests to the WebCenter Sites instance.
OpenCVE Enrichment