Webcenter Interaction
Vendor:
First CVE: Sep 18, 2018 · Active for 7 years
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webcenter Interaction over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2018
7 years ago
Most Recent CVE
Sep 18, 2018
2,866 days ago
CVE Severity & Scoring
Webcenter Interaction8 CVEs
75%
13%
13%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (37.5%)
Unknown0 (0.0%)
Required5 (62.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16957CRITICAL The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this | Sep 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-16952HIGH The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitive actions in the portal (such a | Sep 18, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-16956MEDIUM The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when processing page rename requests. Pages can be renamed to include c | Sep 18, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-16955MEDIUM The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed w | Sep 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16954MEDIUM An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in | Sep 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16953MEDIUM The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User i | Sep 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16959MEDIUM An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows a | Sep 18, 2018 | 5.3 | 19 | NO | NO |
CVE-2018-16958MEDIUM An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Services (IIS) with ASP.NET is used, | Sep 18, 2018 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Webcenter Interaction
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.3.3 | 8 | 6.8 | 1.3% | 0 | 0 |