Impact
A flaw in Oracle WebCenter Sites allows an attacker without authentication to use HTTP requests to create, delete, or modify data stored in the application. This vulnerability arises from missing access control (CWE‑284) and can also trigger a partial denial of service. The impact is limited to the integrity and availability of the application; confidentiality is not directly impacted. The CVSS v3.1 score of 8.2 reflects high severity.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are used to deliver web content and data management services. No other Oracle product is listed as impacted.
Risk and Exploitability
The CVSS base score of 8.2 indicates a strong impact if exploited. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the URL‑based attack path and lack of authentication requirements suggest a high likelihood of exploitation from the Internet or an internal network. An attacker could manipulate critical data or disrupt service without any user credentials.
OpenCVE Enrichment