Impact
A vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to bypass authentication and gain full control of the application. The flaw enables a complete takeover, potentially exposing sensitive data, altering application content, and rendering the site unavailable. The impact is a critical compromise of confidentiality, integrity, and availability of the WebCenter Sites service. Based on the description, the attacker could possibly execute arbitrary code as the application, but this is inferred rather than explicitly stated by the source.
Affected Systems
The affected product is Oracle WebCenter Sites, specifically versions 12.2.1.4.0 and 14.1.2.0.0, which form part of Oracle Fusion Middleware. Systems running these versions are vulnerable if the application accepts HTTP requests from untrusted networks.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user sending crafted HTTP requests through a public or exposed network to a WebCenter Sites instance. Successful exploitation would result in application takeover, effectively allowing the attacker to perform any action that the web application permits, including malicious code execution, data exfiltration, or denial of service.
OpenCVE Enrichment