Skip to Main Content

Application Development Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

how to avoid the use of ucm direct url in production system

778047Apr 7 2014 — edited Apr 8 2014

Hi,

We have built a webcenter enabled custom application (Internet). Contents are being fetched from ucm using RIDC and Content Presenter task flows. Let's say a section has Image and Text parts. We have built CDF which consisting of these two elements. For images we have selected the image from UCM. In our Internet website, wherever images are being displayed, we are getting the direct url (http://domainname/cs/idcplg?IdcService=GET_FILE&dDocName=document_004085&RevisionSelectionMethod=LatestReleased) which is exposed.

Our client has raised a vulnerability defect that ucm url is getting exposed.

Please suggest how to avoid this ?

Thanks,

Bhaskar

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on May 6 2014
Added on Apr 7 2014
5 comments
2,388 views