Unauthorized Access Vulnerability in Oracle WebCenter Sites by Oracle
CVE-2019-2579

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

A vulnerability exists in the Advanced UI component of Oracle WebCenter Sites, part of Oracle Fusion Middleware. This issue allows a low-privileged attacker with network access via HTTP to gain unauthorized read access to sensitive data hosted within Oracle WebCenter Sites. Attackers can exploit this vulnerability to compromise the confidentiality of the exposed data, potentially leading to significant information leaks.

Affected Version(s)

WebCenter Sites 12.2.1.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.