Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
HIGH Availability impact
NONE network
low complexity
oracle
nessus
Published: 2017-10-19
Updated: 2019-10-03
Summary
Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N).
Vulnerable Configurations
Part | Description | Count |
Application | Oracle | 3 |
Nessus
NASL family | CGI abuses |
NASL id | ORACLE_WEBCENTER_CONTENT_OCT_2017_CPU.NASL |
description | The version of Oracle WebCenter Content running on the remote host is affected by an unspecified flaw in the Content Server component that allows an unauthenticated, remote attacker to impact confidentiality and integrity. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 103987 |
published | 2017-10-19 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/103987 |
title | Oracle WebCenter Content Server Component Unspecified Issue (October 2017 CPU) |