Impact
Oracle WebCenter Sites is vulnerable to an unauthenticated, network-accessible flaw that enables attackers to execute arbitrary code on the host. The flaw arises from improper authentication handling (CWE-287) and the use of insecure default credentials (CWE-306). Successful exploitation results in complete takeover of the application, compromising confidentiality, integrity, and availability of all hosted content.
Affected Systems
The affected products are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware. These versions are listed as impacted in the Oracle advisory and confirmed by the CVE description.
Risk and Exploitability
The vulnerability has a CVSS 3.1 score of 9.8, indicating critical severity. The EPSS score is below 1 %, suggesting a low likelihood of widespread active exploitation at present, and it is not yet listed in the CISA KEV catalog. Nonetheless, the attack vector is local network access over HTTP and requires no prior authentication, so any exposed instance is at high risk of compromise.
OpenCVE Enrichment