S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-2791 Scanner

CVE-2018-2791 scanner - Cross-Site Scripting (XSS) vulnerability in Oracle WebCenter Sites

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-2791
8.2
CVSS

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WebCenter Sitesby Oracle Corporation
11.1.1.8.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebCenter Sites is a powerful content management system designed for enterprises to manage their digital assets. This software is used to create, manage, and publish web content, which can be accessed by users browsing the internet. It is popular among businesses because of its scalability, flexibility, and ability to integrate with different systems. However, with the increasing usage of this software, the potential risks and vulnerabilities have also increased.

One such vulnerability is known as CVE-2018-2791. This vulnerability is present in the Advanced UI component of Oracle Fusion Middleware, which is used to create custom user interfaces. This vulnerability can be exploited by an attacker without authentication, with the help of network access via HTTP. It requires human interaction from a person other than the attacker and can have significant impacts on other products associated with Oracle WebCenter Sites.

If this vulnerability is exploited successfully, it can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. The attacker can also gain unauthorized update, insert or delete access to some of the data. The confidentiality and integrity impacts of this vulnerability are rated high, with a CVSS 3.0 Base Score of 8.2.

s4e.io is a powerful platform that provides in-depth information about vulnerabilities in digital assets, including Oracle WebCenter Sites. By leveraging the pro features of this platform, you can easily and quickly learn about the vulnerabilities present in your digital assets and take the necessary steps to protect your data. With s4e.io, you can secure your digital assets proactively and enjoy peace of mind.

 

REFERENCES

Solution Advice

There are several precautions that one can take to protect against this vulnerability. Here are some recommended best practices:

  • Apply the latest patches and updates for Oracle WebCenter Sites as soon as they are available.
  • Implement strict security controls such as firewalls and intrusion prevention systems to monitor network traffic.
  • Train employees to recognize and report suspicious activity promptly.
  • Regularly conduct vulnerability scans and penetration tests to detect any weaknesses in the software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-2791 scanner - Cross-Site Scripting (XSS) vulnerability in Oracle WebCenter Sites | S4E