Impact
A vulnerability in Oracle WebCenter Sites permits an attacker with network access to HTTP to bypass authentication and retrieve or alter data. The flaw allows unauthenticated users to read sensitive data and to perform unauthorized insert, update or delete operations. The impact includes confidentiality compromise for critical information and integrity violations, but the application itself remains available.
Affected Systems
Affected versions are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation. Any deployment of these releases is at risk if no mitigation has been applied.
Risk and Exploitability
The CVSS 3.1 score of 8.2 indicates a high severity with significant confidentiality impact and moderate integrity impact. Exploitation requires no credentials and is reachable over the network via HTTP, implying that an attacker can be a remote threat actor with network visibility. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of prior exploitation does not reduce the risk posed by the exploitability score and the nature of the attack vector.
OpenCVE Enrichment