CVE-2018-16958 Information
Feb 14, 2021
cve
Description
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie when Internet Information Services (IIS) with ASP.NET is used is not protected with the HttpOnly attribute. The attribute cannot be enabled by customers. Consequently this cookie is exposed to session hijacking attacks should an adversary be able to execute JavaScript in the origin of the portal installation. NOTE: this CVE is assigned by MITRE and isn’t validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Reference
http://www.securityfocus.com/bid/105350 https://seclists.org/fulldisclosure/2018/Sep/22
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: