Impact
A vulnerability in Oracle WebCenter Sites allows a low‑privileged attacker who can reach the system over HTTP to compromise the entire application. Exploitation can lead to full takeover, compromising confidentiality, integrity, and availability of all data stored or processed by WebCenter Sites. The weakness is an improper access control mechanism that permits unauthorized execution of privileged functions. The CVSS v3.1 base score of 8.8 reflects severe overall impact and the ease of exploitation for attackers who can connect over the network with minimal effort.
Affected Systems
Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in both releases of the product, which is part of Oracle Fusion Middleware.
Risk and Exploitability
With a network‑based attack surface and a low‑privilege prerequisite, the risk of exploitation is high for systems on the public network. The EPSS score of less than 1% indicates a very low overall probability of exploitation in the wild, but the severity remains high. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted HTTP requests that trigger privileged actions without authentication or by bypassing existing authorization checks.
OpenCVE Enrichment