Impact
Oracle WebCenter Sites is vulnerable to a remote code execution flaw that allows an attacker with low privileges and network access over HTTP to take over the system. The flaw is easily exploitable and results in a complete compromise of confidentiality, integrity, and availability by allowing the attacker to execute arbitrary code on the server. The impact is a full takeover of the WebCenter Sites application.
Affected Systems
The affected product is Oracle WebCenter Sites from Oracle Fusion Middleware. Versions 12.2.1.4.0 and 14.1.2.0.0 are impacted; no other P/E versions are listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 Base Score of 9.9 and has a low exploit probability of less than 1% according to EPSS, but it is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP, with the attacker only needing low privileges and no user interaction. Because the vector includes a scope change, successful exploitation could affect additional components beyond WebCenter Sites, amplifying the enterprise risk. Given the high damage potential, the risk level remains critical even though real‑world exploitation is currently unlikely.
OpenCVE Enrichment