{
    "id": "CVE-2013-1509",
    "published": "2013-04-17 12:14:52",
    "last_modified": "2026-06-16 23:51:34",
    "cvss_score": "4.0",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
    "cwe": null,
    "description": "Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 allows remote authenticated users to affect integrity via unknown vectors related to WebCenter Sites.",
    "epss_score": "0.02207",
    "epss_percentile": "0.82034",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-07 18:17:10",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "oracle",
            "product": "fusion_middleware"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "24964",
            "title": "Oracle WebCenter Sites Satellite Server - HTTP Header Injection",
            "date": "2013-04-18",
            "url": "https://www.exploit-db.com/exploits/24964"
        }
    ],
    "refs_list": [
        "http://archives.neohapsis.com/archives/bugtraq/2013-04/0189.html",
        "http://www.mandriva.com/security/advisories?name=MDVSA-2013:150",
        "http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html",
        "http://archives.neohapsis.com/archives/bugtraq/2013-04/0189.html",
        "http://www.mandriva.com/security/advisories?name=MDVSA-2013:150",
        "http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html"
    ]
}