Impact
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 contain an access‑control weakness that lets an unauthenticated attacker bypass authentication and read any data exposed by the application. The flaw, identified as CWE‑284, enables full read access to all content managed by the site, compromising confidentiality while leaving integrity and availability unaffected.
Affected Systems
The vulnerability impacts Oracle WebCenter Sites under the Oracle Fusion Middleware umbrella. Specifically, the 12.2.1.4.0 release and the 14.1.2.0.0 release are affected. Both versions are accessible through regular HTTP endpoints, and the weakness can be exercised on any hosted instance of the product.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high risk, driven by a network attack vector that requires low effort and no special privileges. The EPSS score of less than 1% indicates a very low probability of current exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is unauthenticated network access over HTTP; an adversary can exploit the flaw from any position on the network that can reach the WebCenter Sites instance, obtaining unrestricted read access to confidential data.
OpenCVE Enrichment