Impact
The vulnerability in Oracle WebCenter Sites, an access‑control flaw (CWE-284), allows a high‑privileged attacker with network access via HTTP to compromise the entire application. An attacker can execute arbitrary commands, resulting in a full takeover of the WebCenter Sites instance. The impact spans confidentiality, integrity, and availability, as the CVSS vector indicates high impact to all three dimensions.
Affected Systems
Affected versions are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0. Both releases are part of Oracle Fusion Middleware and are vulnerable if no patch is applied.
Risk and Exploitability
The CVSS base score of 9.1 reflects high severity. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning there are no known active exploits at this time. However, the attack vector is network‑based, requires high privilege, and poses a significant risk to any environment exposing WebCenter Sites to external traffic.
OpenCVE Enrichment