Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Is this CVE running in your environment?
Easily map the attack path and prioritize which CVEs are a threat to your organization
Vulnerability Intelligence Miggo AI
Unlock WAF rules for this CVE
Generate vendor-ready rules for the observed attack patterns, plus reasoning and safe deployment guidance
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
