Vulnerability record · CVE-2013-1559 · published 17 April 2013
CVE-2013-1559: Oracle WebCenter Content availability flaw via unknown vectors
Oracle · Fusion Middleware
CVE-2013-1559 is an unspecified vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0. Oracle's advisory and NVD provide no technical detail on the root cause, so the exact flaw type is unknown. It matters because a remote authenticated user can degrade availability of Content Server, and the record is too thin to scope the exposure precisely.
Description
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server.
AV:N/AC:L/Au:S/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is network reachable but requires authentication and only affects availability, with no confirmed exploitation and no technical detail to raise severity.
What it is
CVE-2013-1559 is an unspecified vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0. Oracle's advisory and NVD provide no technical detail on the root cause, so the exact flaw type is unknown. It matters because a remote authenticated user can degrade availability of Content Server, and the record is too thin to scope the exposure precisely.
Impact
An attacker who already holds valid credentials can affect availability of the Content Server component, causing partial denial of service. There is no reported impact to confidentiality or integrity.
Attack surface
The vulnerability is reachable over the network (AV:N) with low attack complexity, but requires authentication (Au:S) and no user interaction. It is confined to the Content Server portion of Oracle WebCenter Content.
Exploitation
CISA KEV does not list this CVE, and the only references are the Oracle CPU April 2013 advisory and a Mandriva advisory, with no public exploit or exploitation reports. EPSS is high (0.588, 99th percentile), but that score reflects model output rather than confirmed in-the-wild activity.
What to do
- Apply the Oracle Critical Patch Update April 2013 fixes for WebCenter Content 10.1.3.5.1 and 11.1.1.6.0, or upgrade to a supported release.
- Restrict network access to Content Server interfaces to trusted users and networks.
- Enforce least privilege and review which accounts can reach Content Server, since exploitation requires authentication.
- Monitor Content Server availability and restart or failover behavior for unexplained degradation.
- Track Oracle's advisory for any later clarification of the affected vectors.
Detection
- Alert on repeated Content Server errors, timeouts or service restarts that correlate with authenticated sessions.
- Baseline normal Content Server request rates per account and flag anomalies from low-privilege users.
- Review authentication logs for unusual access patterns to WebCenter Content endpoints.
- Correlate availability incidents with the specific WebCenter Content versions in inventory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1559 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1559), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.