{"api_version":"1","generated_at":"2026-07-23T10:58:14+00:00","cve":"CVE-2013-3770","urls":{"html":"https://cve.report/CVE-2013-3770","api":"https://cve.report/api/cve/CVE-2013-3770.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-3770","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-3770"},"summary":{"title":"CVE-2013-3770","description":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to \"iDoc script injection\" in the (1) cs and (2) urm components, which allows attackers to read \"sensitive\" files, as demonstrated by obtaining the \"AES encryption key and encrypted credentials\" of the weblogic user.","state":"PUBLISHED","assigner":"oracle","published_at":"2013-07-17 13:41:16","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","name":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Critical Patch Update - July 2013","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/54227","name":"http://secunia.com/advisories/54227","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA54227 - Oracle WebCenter Content Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/61228","name":"http://www.securityfocus.com/bid/61228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle WebCenter Content CVE-2013-3770 Remote Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1028801","name":"http://www.securitytracker.com/id/1028801","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Fusion Middleware Bugs Let Remote Users Deny Service and Access and Modify Data - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85658","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/95271","name":"http://osvdb.org/95271","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038","name":"http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle WebCenter Content iDoc Injection Vulnerability","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-3770","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3770","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"3770","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"10.1.3.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3770","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"11.1.1.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3770","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"11.1.1.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:22:01.453Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20130716 Oracle WebCenter Content iDoc Injection Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html"},{"name":"54227","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/54227"},{"name":"95271","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/95271"},{"name":"61228","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/61228"},{"name":"1028801","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1028801"},{"name":"oracle-cpujuly2013-cve20133770(85658)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85658"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-07-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to \"iDoc script injection\" in the (1) cs and (2) urm components, which allows attackers to read \"sensitive\" files, as demonstrated by obtaining the \"AES encryption key and encrypted credentials\" of the weblogic user."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"20130716 Oracle WebCenter Content iDoc Injection Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html"},{"name":"54227","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/54227"},{"name":"95271","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/95271"},{"name":"61228","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/61228"},{"name":"1028801","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1028801"},{"name":"oracle-cpujuly2013-cve20133770(85658)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85658"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2013-3770","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to \"iDoc script injection\" in the (1) cs and (2) urm components, which allows attackers to read \"sensitive\" files, as demonstrated by obtaining the \"AES encryption key and encrypted credentials\" of the weblogic user."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20130716 Oracle WebCenter Content iDoc Injection Vulnerability","refsource":"IDEFENSE","url":"http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html"},{"name":"54227","refsource":"SECUNIA","url":"http://secunia.com/advisories/54227"},{"name":"95271","refsource":"OSVDB","url":"http://osvdb.org/95271"},{"name":"61228","refsource":"BID","url":"http://www.securityfocus.com/bid/61228"},{"name":"1028801","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1028801"},{"name":"oracle-cpujuly2013-cve20133770(85658)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85658"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2013-3770","datePublished":"2013-07-17T10:00:00.000Z","dateReserved":"2013-06-03T00:00:00.000Z","dateUpdated":"2024-08-06T16:22:01.453Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-07-17 13:41:16","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:10.1.3.5.1:*:*:*:*:*:*:*","matchCriteriaId":"8AE0FCD1-EF34-4FAD-854B-1F3545F41CF8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:11.1.1.6.0:*:*:*:*:*:*:*","matchCriteriaId":"6935E726-6AA6-468F-AAEB-BC679FD5CFFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E8934DB1-B2A1-4C3B-B000-78826FC45C7C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"3770","Ordinal":"1","Title":"CVE-2013-3770","CVE":"CVE-2013-3770","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"3770","Ordinal":"1","NoteData":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to \"iDoc script injection\" in the (1) cs and (2) urm components, which allows attackers to read \"sensitive\" files, as demonstrated by obtaining the \"AES encryption key and encrypted credentials\" of the weblogic user.","Type":"Description","Title":"CVE-2013-3770"},{"CveYear":"2013","CveId":"3770","Ordinal":"2","NoteData":"2013-07-17","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"3770","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}