Aerosol Posted January 22, 2015 Report Posted January 22, 2015 Threat Level: HighSeverity: HighCVSS Severity Score: 7.0Impact Type: Complete confidentiality, integrity and availability violation. [2]Vulnerability: (1) Filtration Bypass. (3) Unauthenticated Cross Site scripting vulnerabilities. DescriptionA malicious user could get unsuspecting visitors into divulging their credentials, to force a redirection to aheterogeneous third-party website, or to execute malicious code, on behalf of the attacker. An attacker can alsofold malicious content into the content being delivered to visitors on the site.In this attack “Visitor -> Vendor” trust-levels are directly impacted, since the vendor’s website, and associatedservices , and products have high levels of trust by default. Read more: http://dl.packetstormsecurity.net/1501-advisories/Oracle_Website_Vulnerabilities119.pdf Quote