CVE-2017-10075
published 2017-08-08CVE-2017-10075: Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are…
PriorityP263high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EXPLOIT
EPSS
17.56%
96.8th percentile
Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | webcenter_content | — | — |
| oracle | webcenter_content | — | — |
| oracle | webcenter_content | — | — |
| oracle_corporation | webcenter_content | — | — |
| oracle_corporation | webcenter_content | — | — |
| oracle_corporation | webcenter_content | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=XXXXXXXXXXXX&dSecurityGroup=&QueryText=(dInDate+>=+%60%60)&PageTitle=OO
url/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=AAA&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=XXXXXXXXXXXX
path/cs/idcplg
otherORACLE_QUERY
- →Use the Google dork inurl:"/cs/idcplg" to identify exposed Oracle WebCenter Content servers susceptible to this CVE.
- →The template uses stop-at-first-match across two probe URLs; the second probe uses the IdcScript expression %3C$dateCurrent(-7)$%3E as a canary payload — flag any request containing this encoded string.
- ·Affected versions are strictly 11.1.1.9.0, 12.2.1.1.0, and 12.2.1.2.0 — detections should be scoped to these versions to reduce false positives. ↗
- ·The vulnerability requires human interaction (UI:R in CVSS vector), meaning exploitation is XSS-based and requires a victim to visit a crafted URL — purely server-side detections will miss the client-side impact. ↗
- ·The Nuclei template is verified and has a very high EPSS score (0.86251, 99.4th percentile), indicating this vulnerability is actively exploited in the wild — prioritise detection accordingly.
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Oracle Content Server - Cross-Site Scripting
nuclei·CVSS 8.2
CVE-2017-10075 [HIGH] Oracle Content Server - Cross-Site Scripting
Oracle Content Server - Cross-Site Scripting
Oracle Content Server version 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0 are susceptible to cross-site scripting. The vulnerability can be used to include HTML or JavaScript code in the affected web page. The code is executed in the browser of users if they visit the manipulated site.
Template:
id: CVE-2017-10075
info:
name: Oracle Content Server - Cross-Site Scripting
author: madrobot
severity: high
description: |
Oracle Content Server version 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0 are susceptible to cross-site scripting. The vulnerability can be used to include HTML or JavaScript code in the affected web page. The code is executed in the browser of users if they visit the manipulated site.
impact: |
Successful exploitation of this vulnerability
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99807http://www.securitytracker.com/id/1038940http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99807http://www.securitytracker.com/id/1038940
2017-08-08
Published