CVE-2018-16954

MEDIUM

Oracle WebCenter Interaction Portal 10.3.3 - Open Redirect

Title source: llm
STIX 2.1

Description

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application after a successful login. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.

References (2)

Core 2
Core References
Exploit, Mailing List, Patch, Third Party Advisory x_refsource_misc
https://seclists.org/fulldisclosure/2018/Sep/22
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105350

Scores

CVSS v3 6.1
EPSS 0.0107
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
oracle/webcenter_interaction 10.3.3
Published Sep 18, 2018
Tracked Since Feb 18, 2026