Impact
The vulnerability in Oracle WebCenter Sites enables an unauthenticated attacker who can reach the system over HTTP to compromise the entire application. Successful exploitation results in full takeover of the site, allowing the attacker to read, modify, delete data, and execute arbitrary code with the privileges of the application. This flaw delivers complete confidentiality, integrity, and availability disruption, reflected by a CVSS 3.1 base score of 9.8.
Affected Systems
Affected versions are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw applies to the WebCenter Sites component as identified by Oracle.
Risk and Exploitability
The vulnerability is easily exploitable, with no authentication required and only standard network access to HTTP ports. The current EPSS score is not available, but the high CVSS score and lack of upstream mitigations underline a severe risk. The flaw is not listed in CISA KEV, so no public exploit benchmarks exist yet. The CVSS vector indicates that an attacker can achieve full confidentiality, integrity, and availability impact through remote code execution.
OpenCVE Enrichment