CVE-2018-16957
Last modified
CVE-2018-16957 is a vulnerability of currently unknown severity. The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this hardcoded password and cannot be customised by customers. EPSS estimates a 3.44% chance of exploitation in the next 30 days.
Description
The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this hardcoded password and cannot be customised by customers. An adversary able to access this service over a network could perform search queries to extract large quantities of sensitive information from the WCI installation. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Webcenter Interaction | 10.3.3 |
References
- http://www.securityfocus.com/bid/105350Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Sep/22Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105350Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Sep/22Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16957?
How severe is CVE-2018-16957?
How do I fix CVE-2018-16957?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16951xunfeng 0.2.0 allows command execution via CSRF because mass…
- CVE-2018-16952The Oracle WebCenter Interaction Portal 10.3.3 does not impl…
- CVE-2018-16953The AjaxView::DisplayResponse() function of the portalpages.…
- CVE-2018-16954An issue was discovered in Oracle WebCenter Interaction Port…
- CVE-2018-16955The login function of Oracle WebCenter Interaction Portal 10…
- CVE-2018-16956The AjaxControl component of Oracle WebCenter Interaction Po…
- CVE-2018-16958An issue was discovered in Oracle WebCenter Interaction Port…
- CVE-2018-16959An issue was discovered in Oracle WebCenter Interaction Port…
- CVE-2018-16960An issue was discovered in Open XDMoD through 7.5.0. html/gu…
- CVE-2018-16961An issue was discovered in Open XDMoD through 7.5.0. html/gu…
- CVE-2018-16962Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles a…
- CVE-2018-16965In Zoho ManageEngine SupportCenter Plus before 8.1 Build 810…
Are you affected by CVE-2018-16957?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
