Insecure User Profile Configuration in Oracle WebCenter Interaction Portal
CVE-2018-16959
What is CVE-2018-16959?
An issue has been identified in Oracle WebCenter Interaction Portal version 10.3.3, where the default User Profile community configuration is insecure. This misconfiguration allows anonymous users to access and retrieve the account names of all registered portal users via specific request endpoints. Furthermore, if the portal is integrated with Active Directory, the vulnerability could extend to exposing the account names of all Active Directory users, significantly jeopardizing user information security. This vulnerability was identified by MITRE but has not been validated by Oracle due to the product being out of support.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved