Impact
A flaw in Oracle WebCenter Sites version 14.1.2.0.0 permits an unauthenticated attacker with network access over HTTP to fully compromise the application. The vulnerability stems from missing or broken authorization and authentication controls, allowing arbitrary code execution and takeover of the site. This impacts confidentiality, integrity, and availability, and is classified as CWE-284 and CWE-306.
Affected Systems
Oracle WebCenter Sites, part of Oracle Fusion Middleware, version 14.1.2.0.0. All installations that expose the WebCenter Sites HTTP interface to a network without requiring prior user authentication are affected.
Risk and Exploitability
The CVSS base score of 9.8 reflects a critical severity. The EPSS score of less than 1% indicates that, in the current landscape, exploitation in the wild is infrequent, yet the vulnerability remains highly dangerous if discovered. It is not listed in the CISA KEV catalog. Exploitation requires only network connectivity to the HTTP endpoint and does not require credentials, meaning any publicly exposed instance could be targeted.
OpenCVE Enrichment