Impact
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected by an easily exploitable vulnerability that lets a low privileged attacker with network access via HTTP compromise the system. Successful exploitation can result in the attacker taking complete control of the WebCenter Sites instance, with significant confidentiality, integrity, and availability impacts as indicated by a CVSS 3.1 base score of 9.9. While the description does not explicitly state remote code execution, the potential for complete takeover implies that remote code execution is likely; this inference is based on the described impact. The CVSS vector suggests that the attack is network‑based, requires low attacker privileges, no user interaction, and the compromise effect extends beyond the vulnerable product, potentially affecting other related Oracle Fusion Middleware components.
Affected Systems
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The vulnerability can be triggered over the network through HTTP, with a low privileged attacker able to exploit it. CVSS analysis shows a high severity score of 9.9, with an EPSS score of less than 1 % and not listed in the CISA KEV catalog. The attack vector is network based, the impact is widespread due to scope changes that may affect additional products, and the vulnerability is highly exploitable given its simplicity and the low privilege requirement.
OpenCVE Enrichment