Impact
A vulnerability in Oracle WebCenter Sites allows a low‑privileged attacker with network access via HTTP to compromise the application. Exploitation can lead to full takeover, impacting confidentiality, integrity, and availability of the system. The weakness stems from inadequate protection against remote code execution through the web interface.
Affected Systems
The affected products are Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. No other versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity with network access, low attack complexity, and low privileges required. The EPSS score is reported as less than 1 %, meaning exploitation probability is currently very low but not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over HTTP; an attacker with a low‑privileged account can exploit the flaw to execute code and gain control of the WebCenter Sites instance.
OpenCVE Enrichment