Impact
The Oracle WebCenter Sites component has an authentication bypass that permits unauthenticated HTTP requests to perform privileged operations such as creating, deleting, or modifying site content. Successful exploitation could let an attacker alter critical data or remove content and also cause a partial denial of service by disrupting access to legitimate users. The flaw is identified as an improper authentication and access control weakness, allowing attackers to subvert the intended security model.
Affected Systems
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 8.2, which denotes a high‑severity vulnerability with the ability to compromise data integrity and partially disrupt availability. Because the flaw is exploitable over HTTP without authentication, an attacker with network access can launch the attack remotely. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would use standard HTTP requests without authentication to exploit the flaw.
OpenCVE Enrichment