Impact
A vulnerability in Oracle WebCenter Sites allows a low‑privileged attacker with network access via HTTP to potentially compromise the application. Successful exploitation could lead to a full takeover, thereby affecting confidentiality, integrity, and availability of the system. The weakness appears to stem from inadequate protection that could enable an attacker to execute arbitrary actions through the web interface, though the CVE description does not explicitly state remote code execution and this conclusion is an inference based on the stated impact.
Affected Systems
The affected products are Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. No other versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity with network access, low attack complexity, and low privileges required. The EPSS score is reported as less than 1 %, meaning the exploitation probability appears to be very low at present, though not zero. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over HTTP; a low‑privileged attacker could potentially exploit the flaw to gain control of the WebCenter Sites instance.
OpenCVE Enrichment