Impact
Easily exploitable vulnerability in Oracle WebCenter Sites allows an attacker with low privileges and network access via HTTP to compromise the application. Successful exploitation results in full takeover, giving the attacker full confidentiality, integrity, and availability control over the affected instance.
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw is present in the Fusion Middleware component WebCenter Sites core product.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high severity. The attack vector is inferred to be over HTTP, with low assurance and no required user interaction. No EPSS score is available and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation at this time. Because the attacker needs only local or remote network access and can elevate to full takeover, the risk to systems with exposed WebCenter Sites is significant.
OpenCVE Enrichment