Oracle WebCenter Portal Multiple Vulnerabilities (July 2015 CPU)

medium Nessus Plugin ID 84916

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The remote host has a version of Oracle WebCenter Portal installed that is affected by the following vulnerabilities :

- A flaw exists in Oracle's implementation of the JSR (Java Specification Request) 286 Portlet Specification functionality. A remote, authenticated attacker can exploit this, via crafted portal URL, to affect confidentiality and integrity. (CVE-2015-1926)

- A security bypass vulnerability exists in the Portlet Bridge for JavaServer Faces due to a failure to properly restrict access to resources in web applications. A remote attacker can exploit this, via a URL with a modified resource ID, to disclose sensitive information.
(CVE-2015-3244)

Solution

Apply the appropriate patch according to the July 2015 Oracle Critical Patch Update advisory.

See Also

http://www.nessus.org/u?d18c2a85

Plugin Details

Severity: Medium

ID: 84916

File Name: oracle_webcenter_portal_july_2015_cpu.nbin

Version: 1.165

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 7/22/2015

Updated: 4/15/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2015-1926

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:fusion_middleware

Required KB Items: installed_sw/Oracle WebCenter Portal

Exploit Ease: No known exploits are available

Patch Publication Date: 7/14/2015

Vulnerability Publication Date: 7/14/2015

Reference Information

CVE: CVE-2015-1926, CVE-2015-3244

BID: 75860, 75941