S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-10075 Scanner

CVE-2017-10075 scanner - Cross-Site Scripting (XSS) vulnerability in Oracle WebCenter Content

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-10075
8.2
CVSS

Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WebCenter Contentby Oracle Corporation
11.1.1.9.0
Updated Aug 22, 2026View on NVD →
Detail

Oracle WebCenter Content is a component of Oracle Fusion Middleware which serves as a content management system. This software allows users to manage content in an efficient and secure manner. Primarily used by large enterprises, Oracle WebCenter Content is a popular solution to meet the document needs of businesses.

CVE-2017-10075 is a vulnerability that was detected in Oracle WebCenter Content. This vulnerability can be easily exploited by an unauthorized attacker who has network access via HTTP. Since the vulnerability can be exploited without authentication, it poses a serious threat to the security of Oracle WebCenter Content and other related products. The impact of this vulnerability can be severe as it allows unauthorized access to sensitive data, unauthorized updates or deletion of critical data.

If the CVE-2017-10075 vulnerability is exploited, it can lead to unauthorized access to critical data stored in the Oracle WebCenter Content system. In some cases, the attackers could gain complete access to all the data stored, leading to a potential data breach. The vulnerability also allows attackers to modify or delete data stored in Oracle WebCenter Content. This could lead to data loss, affect business operations, and cause reputation damage.

Thanks to the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. The platform offers real-time security notifications, vulnerability scanning and threat intelligence. With s4e.io, users can protect their digital assets from potential threats and reduce the risk of damage to their businesses.

 

REFERENCES

Solution Advice

There are some precautions that can be taken to protect against this vulnerability. These include:

  • Apply Oracle's Security Patch Update (SPU) to fix the vulnerability
  • Monitor network activity for suspicious behavior and limit network access where possible
  • Implement firewall rules to limit external communication and create Intrusion Detection/Prevention Systems (IDS/IPS)
  • Educate employees about the importance of security and discourage unsafe behavior

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-10075 scanner - Cross-Site Scripting (XSS) vulnerability in Oracle WebCenter Content | S4E