CVE-2018-16959
Last modified
CVE-2018-16959 is a vulnerability of currently unknown severity. An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to retrieve the account names of all portal users via /portal/server.pt/user/user/ requests. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to retrieve the account names of all portal users via /portal/server.pt/user/user/ requests. When WCI is synchronised with Active Directory (AD), this vulnerability can expose the account names of all AD users. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Webcenter Interaction | 10.3.3 |
References
- http://www.securityfocus.com/bid/105350Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Sep/22Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105350Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Sep/22Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16959?
How severe is CVE-2018-16959?
How do I fix CVE-2018-16959?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16953The AjaxView::DisplayResponse() function of the portalpages.…
- CVE-2018-16954An issue was discovered in Oracle WebCenter Interaction Port…
- CVE-2018-16955The login function of Oracle WebCenter Interaction Portal 10…
- CVE-2018-16956The AjaxControl component of Oracle WebCenter Interaction Po…
- CVE-2018-16957The Oracle WebCenter Interaction 10.3.3 search service query…
- CVE-2018-16958An issue was discovered in Oracle WebCenter Interaction Port…
- CVE-2018-16960An issue was discovered in Open XDMoD through 7.5.0. html/gu…
- CVE-2018-16961An issue was discovered in Open XDMoD through 7.5.0. html/gu…
- CVE-2018-16962Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles a…
- CVE-2018-16965In Zoho ManageEngine SupportCenter Plus before 8.1 Build 810…
- CVE-2018-16966There is a CSRF vulnerability in the mndpsingh287 File Manag…
- CVE-2018-16967There is an XSS vulnerability in the mndpsingh287 File Manag…
Are you affected by CVE-2018-16959?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
