S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-2578 Scanner

CVE-2019-2578 scanner - Broken Access Control vulnerability in Oracle WebCenter Sites

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-2578
8.6
CVSS

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WebCenter Sitesby Oracle Corporation
12.2.1.3.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebCenter Sites is a web content management system that is used by businesses and organizations to create and manage websites, mobile sites, and social media pages. It provides a comprehensive set of tools and capabilities that enable content managers to easily create, manage, and publish content across different channels. It is particularly useful for organizations that require complex website management, such as those in the healthcare, financial, and retail industries.

CVE-2019-2578 is a vulnerability in the Advanced UI subcomponent of Oracle WebCenter Sites. This vulnerability allows an unauthenticated attacker to compromise the system and gain unauthorized access to critical data. The vulnerability can be easily exploited by an attacker with network access via HTTP, which makes it particularly dangerous. The vulnerable version of the software is 12.2.1.3.0, and it affects the confidentiality of data.

Exploitation of the vulnerability can lead to unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. This can have serious consequences for businesses and organizations, including the leak of sensitive data, financial loss, and reputational damage. Moreover, the vulnerability can also lead to further attacks on other products that are supported by Oracle WebCenter Sites. Therefore, it is important to take timely precautions to protect against this vulnerability.

Thanks to the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability assessment, scanning, and reporting features that enable organizations to identify and remediate vulnerabilities before they are exploited by attackers. With s4e.io, businesses can ensure the security and reliability of their online presence, without compromising their productivity or operations.

 

REFERENCES

Solution Advice

There are several precautions that organizations can take to protect their systems against CVE-2019-2578, including:

  • Applying security patches provided by Oracle to fix the vulnerability.
  • Disabling unused components and functionalities to reduce the attack surface.
  • Implementing network segmentation and access controls to prevent unauthorized access to critical data.
  • Monitoring the system and detecting suspicious activities or unauthorized access attempts.
  • Educating end-users on best practices for improving the system's security, such as using strong passwords and avoiding clicking on suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-2578 scanner - Broken Access Control vulnerability in Oracle WebCenter Sites S4E