Impact
A vulnerability in Oracle WebCenter Sites allows a low‑privileged attacker with network access through HTTP to compromise the application and achieve full takeover. This issue represents improper access control (CWE-284). The confirmed CVSS 3.1 base score of 8.8 reflects complete confidentiality, integrity, and availability impact. The vulnerability is easily exploitable and does not require elevated privileges or additional authentication steps.
Affected Systems
Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0.0 are afflicted. These are the only products listed as affected in the CNA data.
Risk and Exploitability
The attack vector is a remote network interaction via HTTP. Because the exploit requires only low privileged access, an adversary can trigger it from outside the protected network. With a CVSS 8.8 score and an EPSS score of less than 1%, the threat remains significant; the vulnerability is not listed in CISA’s KEV catalog, but the lack of additional mitigations in the environment elevates the risk.
OpenCVE Enrichment