Impact
Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0.0 contain a vulnerability that allows an attacker with low privileges and network access through HTTP to compromise the application. Successful exploitation can lead to full takeover, resulting in loss of confidentiality, integrity, and availability. The weakness is classified under CWE-284.
Affected Systems
Affected vendor is Oracle Corporation, product Oracle WebCenter Sites in Oracle Fusion Middleware. Versions impacted are 12.2.1.4.0 and 14.1.2.0.0. No other releases are reported.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, indicating high severity. The EPSS score is 0.00447, which represents a very low but non‑zero exploit probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based HTTP traffic; attackers only need a low privilege level, and authentication does not appear to be bypassed, so the endpoint is reachable without elevated rights.
OpenCVE Enrichment