Impact
A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to compromise the system. Successful exploitation can lead to unauthorized reading of critical data, as well as inserting, updating, or deleting data, and can induce a partial denial of service. The primary weakness is improper access control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L.
Affected Systems
Oracle WebCenter Sites product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other vendors or product families are listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.6, indicating high severity. The EPSS score of less than 1% indicates that exploitation probability is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The CVSS vector shows a remote attack over an insecure HTTP protocol with no authentication required, meaning any network user could attempt to abuse the flaw. Because it can lead to unauthorized data access, modification, and partial service disruption, the risk remains significant for organizations running these versions.
OpenCVE Enrichment