HTTP: Oracle WebCenter Content CheckOutAndOpen.dll ActiveX Control Code Execution

This signature detects attempts to use unsafe ActiveX controls in Oracle WebCenter. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server.

Affected Products

Oracle fusion_middleware

References

BugTraq: 59122

CVE: CVE-2013-1559

Short Name
HTTP:STC:ACTIVEX:ORCLE-WEBCENTR
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2013-1559 CheckOutAndOpen.dll Code Content Control Execution Oracle WebCenter bid:59122
Release Date
08/12/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Oracle

CVSS Score

4.0

Found a potential security threat?