Impact
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 contain a flaw that allows an unauthenticated attacker with HTTP network access to read, insert, update, or delete site data and trigger a partial denial of service. The vulnerability is exploitable through a simple HTTP request and violates the security principle of Improper Access Control (CWE‑284). Successful exploitation grants the attacker unauthorized access to critical data and the ability to compromise confidentiality, integrity, and availability of all data exposed by the WebCenter Sites instance.
Affected Systems
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware, are affected. These releases are commonly deployed in enterprise content and site‑management environments, often exposed to the Internet or internal corporate networks.
Risk and Exploitability
The CVSS v3.1 base score of 8.6 indicates high severity, with high confidentiality impact and lower integrity and availability impact. The EPSS score of less than 1% shows a very low current exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based, requiring only unauthenticated HTTP access, which makes the potential for real‑world exploitation significant if the issue is left unmitigated.
OpenCVE Enrichment