Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
BID:66838
Info
Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
| Bugtraq ID: | 66838 |
| Class: | Design Error |
| CVE: |
CVE-2014-0450 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2014 12:00AM |
| Updated: | May 16 2014 12:52AM |
| Credit: | Alex Zaharis |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
Oracle WebCenter Portal is prone to an information-disclosure vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'People Connection' sub component is affected.
Successfully exploiting this issue may allow an attacker to gain access to sensitive information that may aid in further attacks.
This vulnerability affects the following supported versions:
11.1.1.7, 11.1.1.8
Oracle WebCenter Portal is prone to an information-disclosure vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'People Connection' sub component is affected.
Successfully exploiting this issue may allow an attacker to gain access to sensitive information that may aid in further attacks.
This vulnerability affects the following supported versions:
11.1.1.7, 11.1.1.8
Exploit / POC
Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
The researcher who found the issue has created a proof-of-concept. Please see the references for information.
The researcher who found the issue has created a proof-of-concept. Please see the references for information.
Solution / Fix
Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle WebCenter Portal CVE-2014-0450 Information Disclosure Vulnerability
References:
References: