Impact
There is an easily exploitable vulnerability in Oracle WebCenter Sites that allows an attacker with low privileges and network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover of the WebCenter Sites instance, resulting in complete loss of confidentiality, integrity, and availability for the affected deployment.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. These products are part of Oracle Fusion Middleware and are commonly deployed for web content management and collaboration.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 indicates high severity. The EPSS score of 0.00447 (less than 1%) is available, and the vulnerability is not listed in the CISA KEV catalog, but the minimal attack requirements—network access via HTTP and a low‑privilege user—make exploitation relatively straightforward. The high impact combined with the low attack effort results in a significant risk for organizations running the affected versions.
OpenCVE Enrichment