Impact
The vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker who can reach the system over HTTP to compromise the entire application. Successful exploitation results in full takeover of the site, permitting the attacker to read, modify and delete data, and execute arbitrary code with application privileges. This flaw delivers complete confidentiality, integrity, and availability disruption, reflected by a CVSS 3.1 base score of 9.8.
Affected Systems
Affected versions are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw applies to the WebCenter Sites component as identified by Oracle.
Risk and Exploitability
The vulnerability is easily exploitable, requiring no authentication and only standard HTTP network access. An EPSS score of < 1% indicates a very low probability of exploitation in the wild, but the high CVSS score demonstrates severe potential impact if exploited. The flaw is not listed in the CISA KEV catalog, meaning no publicly known exploit benchmarks exist yet. The CVSS vector shows that the impact covers confidentiality, integrity, and availability.
OpenCVE Enrichment