Impact
A vulnerability in Oracle WebCenter Sites enables a low‑privileged attacker with network reachability through HTTP to compromise the application, potentially taking full control. The exploit impacts confidentiality, integrity, and availability, granting the attacker the same rights as the application itself.
Affected Systems
Affected products are Oracle WebCenter Sites within Oracle Fusion Middleware, specifically the 12.2.1.4.0 and 14.1.2.0.0 releases. The advisory lists these releases as vulnerable, and no later versions are mentioned as fixed. All installations running these versions and exposed over HTTP are potentially at risk.
Risk and Exploitability
This is a high‑severity vulnerability with a CVSS 3.1 base score of 8.8, indicating a high likelihood of successful exploitation using network access and low privilege. The EPSS score is not available, but the vulnerability is listed in Oracle’s advisory and is not yet in the CISA KEV catalog. The likely attack vector is remote via HTTP, and the weakness permits a complete takeover of the target instance.
OpenCVE Enrichment