Impact
An unauthenticated attacker with network access to HTTP can exploit a flaw in Oracle WebCenter Sites to obtain access to critical data and to perform update, insert, or delete operations on that data. The vulnerability exposes confidentiality at a high level and a lower level of integrity impact, and it is rated CVSS 3.1 with a base score of 8.2. This indicates a serious risk that could compromise data confidentiality and allow data manipulation without proper authorization.
Affected Systems
Oracle WebCenter Sites version 12.2.1.4.0 and version 14.1.2.0.0 are vulnerable to the described flaw. Users of these releases should verify their installation version and apply any available vendor updates.
Risk and Exploitability
The known exploitation path involves sending specially crafted HTTP traffic to an unauthenticated WebCenter Sites instance. The CVSS score of 8.2 signals a high severity, while the EPSS score is not available, leaving uncertainty about current exploitation prevalence. The vulnerability is not listed in CISA’s KEV catalog, but given its authentication bypass nature and the potential for data tampering, risk remains substantial for exposed installations.
OpenCVE Enrichment