Insecure User Profile Configuration in Oracle WebCenter Interaction Portal
CVE-2018-16959

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 September 2018

Summary

An issue has been identified in Oracle WebCenter Interaction Portal version 10.3.3, where the default User Profile community configuration is insecure. This misconfiguration allows anonymous users to access and retrieve the account names of all registered portal users via specific request endpoints. Furthermore, if the portal is integrated with Active Directory, the vulnerability could extend to exposing the account names of all Active Directory users, significantly jeopardizing user information security. This vulnerability was identified by MITRE but has not been validated by Oracle due to the product being out of support.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.