Insecure User Profile Configuration in Oracle WebCenter Interaction Portal
CVE-2018-16959
5.3MEDIUM
Summary
An issue has been identified in Oracle WebCenter Interaction Portal version 10.3.3, where the default User Profile community configuration is insecure. This misconfiguration allows anonymous users to access and retrieve the account names of all registered portal users via specific request endpoints. Furthermore, if the portal is integrated with Active Directory, the vulnerability could extend to exposing the account names of all Active Directory users, significantly jeopardizing user information security. This vulnerability was identified by MITRE but has not been validated by Oracle due to the product being out of support.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved