Impact
A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to compromise the system. Successful exploitation can lead to unauthorized reading of critical data, as well as inserting, updating, or deleting data, and can induce a partial denial of service. The primary weakness is improper access control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L.
Affected Systems
Oracle WebCenter Sites product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other vendors or product families are listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.6, indicating high severity. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The vector indicates remote exploitation over an insecure network protocol, and the lack of authentication requirement means any network user could attempt to abuse the flaw. Given the potential for both data compromise and service interruption, the risk is significant for organizations running these software versions.
OpenCVE Enrichment