Impact
A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to compromise the application. The vulnerability can lead to a full takeover of the site, resulting in loss of confidentiality, integrity and availability. The description does not explicitly identify the underlying weakness, but the high impact and lack of authentication requirement point to a missing authorization flaw that permits total control of the site.
Affected Systems
Oracle WebCenter Sites, part of the Oracle Fusion Middleware suite, is affected for versions 12.2.1.4.0 and 14.1.2.0.0. The change in scope noted in the advisory suggests that other connected products in the environment could also be impacted if a successful exploit occurs.
Risk and Exploitability
The CVSS base score of 9.0 indicates a very high severity vulnerability that does not require authentication or user interaction. The EPSS score of <1% indicates a very low probability of exploitation, but the absence of defensive checks makes the attack path straightforward. As the vulnerability is not listed in CISA’s KEV catalog, there is no current evidence of widespread exploitation yet, yet the potential for immediate takeover makes it a critical risk. The likely attack vector involves sending a crafted HTTP request to a vulnerable endpoint. The scope change in the advisory indicates that an exploit could have broader impacts across the middleware stack.
OpenCVE Enrichment