Unauthenticated Network Vulnerability in Oracle WebCenter Sites from Oracle
CVE-2019-2578

8.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

A vulnerability exists in the Oracle WebCenter Sites component of Oracle Fusion Middleware, specifically in the Advanced UI subcomponent. This vulnerability can be exploited easily by an unauthenticated attacker with network access via HTTP, potentially allowing for unauthorized access to critical data. Given its nature, attacks can affect not only the Oracle WebCenter Sites itself but may also significantly impact additional products associated with the environment. Organizations utilizing affected versions must take immediate steps to secure their systems and protect sensitive information from unauthorized access.

Affected Version(s)

WebCenter Sites 12.2.1.3.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.