Impact
A flaw in Oracle WebCenter Sites allows an unauthenticated attacker to exploit the web interface and gain full control of the system. The vulnerability is easily exploitable over standard HTTP traffic and, if successfully leveraged, results in a complete takeover of the WebCenter Sites application, compromising confidentiality, integrity, and availability. The weakness corresponds to authentication failures (CWE‑287) and privilege escalation due to improper access controls (CWE‑306).
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Any deployment of these releases is at risk if they are exposed directly to the network.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of severity. Although the EPSS score is low (< 1%), the vulnerability can be exploited without special privileges and with minimal effort, i.e., by sending a crafted HTTP request. The product is not listed in the CISA KEV catalogue, but the high base score and ease of exploitation make it a top priority for remediation. Attackers can initiate the exploit remotely using any network path to the WebCenter Sites instance.
OpenCVE Enrichment