← Vulnerability feed

Vulnerability record · CVE-2013-1559 · published 17 April 2013

CVE-2013-1559: Oracle WebCenter Content availability flaw via unknown vectors

Oracle · Fusion Middleware

CVE-2013-1559 is an unspecified vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0. Oracle's advisory and NVD provide no technical detail on the root cause, so the exact flaw type is unknown. It matters because a remote authenticated user can degrade availability of Content Server, and the record is too thin to scope the exposure precisely.

4.0 CVSS 2.0 Medium EPSS 59% · top 0.9%
4.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server.

AV:N/AC:L/Au:S/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: low.

medium priorityThe flaw is network reachable but requires authentication and only affects availability, with no confirmed exploitation and no technical detail to raise severity.

What it is

CVE-2013-1559 is an unspecified vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0. Oracle's advisory and NVD provide no technical detail on the root cause, so the exact flaw type is unknown. It matters because a remote authenticated user can degrade availability of Content Server, and the record is too thin to scope the exposure precisely.

Impact

An attacker who already holds valid credentials can affect availability of the Content Server component, causing partial denial of service. There is no reported impact to confidentiality or integrity.

Attack surface

The vulnerability is reachable over the network (AV:N) with low attack complexity, but requires authentication (Au:S) and no user interaction. It is confined to the Content Server portion of Oracle WebCenter Content.

Exploitation

CISA KEV does not list this CVE, and the only references are the Oracle CPU April 2013 advisory and a Mandriva advisory, with no public exploit or exploitation reports. EPSS is high (0.588, 99th percentile), but that score reflects model output rather than confirmed in-the-wild activity.

What to do

  • Apply the Oracle Critical Patch Update April 2013 fixes for WebCenter Content 10.1.3.5.1 and 11.1.1.6.0, or upgrade to a supported release.
  • Restrict network access to Content Server interfaces to trusted users and networks.
  • Enforce least privilege and review which accounts can reach Content Server, since exploitation requires authentication.
  • Monitor Content Server availability and restart or failover behavior for unexplained degradation.
  • Track Oracle's advisory for any later clarification of the affected vectors.

Detection

  • Alert on repeated Content Server errors, timeouts or service restarts that correlate with authenticated sessions.
  • Baseline normal Content Server request rates per account and flag anomalies from low-privilege users.
  • Review authentication logs for unusual access patterns to WebCenter Content endpoints.
  • Correlate availability incidents with the specific WebCenter Content versions in inventory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1559 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2013-1559), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.