CVE-2019-2427
published 2019-01-16CVE-2019-2427: Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). Supported versions that are…
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.27%
66.6th percentile
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | webcenter_portal | — | — |
| oracle | webcenter_portal | — | — |
| oracle_corporation | webcenter_portal | — | — |
| oracle_corporation | webcenter_portal | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5855 chromium-browser: Integer overflow in PDFium
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-5855 [MEDIUM] CVE-2019-5855 chromium-browser: Integer overflow in PDFium
CVE-2019-5855 chromium-browser: Integer overflow in PDFium
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=964872
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5855
Bugzilla
CVE-2019-5860 chromium-browser: Use-after-free in PDFium
bugzilla·2019-08-06·CVSS 5.5
CVE-2019-5860 [MEDIUM] CVE-2019-5860 chromium-browser: Use-after-free in PDFium
CVE-2019-5860 chromium-browser: Use-after-free in PDFium
An use-after-free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=956947
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5860
Bugzilla
CVE-2019-5850 chromium-browser: Use-after-free in offline page fetcher
bugzilla·2019-08-06·CVSS 9.6
CVE-2019-5850 [CRITICAL] CVE-2019-5850 chromium-browser: Use-after-free in offline page fetcher
CVE-2019-5850 chromium-browser: Use-after-free in offline page fetcher
An use-after-free flaw was found in the offline page fetcher component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=977462
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5850
Bugzilla
CVE-2019-5854 chromium-browser: Integer overflow in PDFium text rendering
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5854 [HIGH] CVE-2019-5854 chromium-browser: Integer overflow in PDFium text rendering
CVE-2019-5854 chromium-browser: Integer overflow in PDFium text rendering
An integer overflow flaw was found in the PDFium text rendering component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=966263
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5854
Bugzilla
CVE-2019-5857 chromium-browser: Comparison of -0 and null yields crash
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-5857 [MEDIUM] CVE-2019-5857 chromium-browser: Comparison of -0 and null yields crash
CVE-2019-5857 chromium-browser: Comparison of -0 and null yields crash
The following flaw was identified in the Chromium browser: Comparison of -0 and null yields crash.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=961237
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5857
Bugzilla
CVE-2019-5858 chromium-browser: Insufficient filtering of Open URL service parameters
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5858 [HIGH] CVE-2019-5858 chromium-browser: Insufficient filtering of Open URL service parameters
CVE-2019-5858 chromium-browser: Insufficient filtering of Open URL service parameters
The following flaw was identified in the Chromium browser: Insufficient filtering of Open URL service parameters.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=960209
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5858
Bugzilla
CVE-2019-5859 chromium-browser: res: URIs can load alternative browsers
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5859 [HIGH] CVE-2019-5859 chromium-browser: res: URIs can load alternative browsers
CVE-2019-5859 chromium-browser: res: URIs can load alternative browsers
The following flaw was identified in the Chromium browser: res: URIs can load alternative browsers.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=959438
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5859
Bugzilla
CVE-2019-5856 chromium-browser: Insufficient checks on filesystem: URI permissions
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5856 [HIGH] CVE-2019-5856 chromium-browser: Insufficient checks on filesystem: URI permissions
CVE-2019-5856 chromium-browser: Insufficient checks on filesystem: URI permissions
The following flaw was identified in the Chromium browser: Insufficient checks on filesystem: URI permissions.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=964245
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5856
Bugzilla
CVE-2019-5865 chromium-browser: Site isolation bypass from compromised renderer
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-5865 [MEDIUM] CVE-2019-5865 chromium-browser: Site isolation bypass from compromised renderer
CVE-2019-5865 chromium-browser: Site isolation bypass from compromised renderer
The following flaw was identified in the Chromium browser: Site isolation bypass from compromised renderer.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=973103
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5865
Bugzilla
CVE-2019-5851 chromium-browser: Use-after-poison in offline audio context
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5851 [HIGH] CVE-2019-5851 chromium-browser: Use-after-poison in offline audio context
CVE-2019-5851 chromium-browser: Use-after-poison in offline audio context
An use-after-poison flaw was found in the offline audio context component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=977107
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5851
Bugzilla
CVE-2019-5864 chromium-browser: Insufficient port filtering in CORS for extensions
bugzilla·2019-08-06·CVSS 4.3
CVE-2019-5864 [MEDIUM] CVE-2019-5864 chromium-browser: Insufficient port filtering in CORS for extensions
CVE-2019-5864 chromium-browser: Insufficient port filtering in CORS for extensions
An insufficient port filtering flaw was found in the CORS for extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=936900
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5864
Bugzilla
CVE-2019-5853 chromium-browser: Memory corruption in regexp length check
bugzilla·2019-08-06·CVSS 8.8
CVE-2019-5853 [HIGH] CVE-2019-5853 chromium-browser: Memory corruption in regexp length check
CVE-2019-5853 chromium-browser: Memory corruption in regexp length check
A memory corruption flaw was found in the regexp length check component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=976627
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5853
Bugzilla
CVE-2019-5861 chromium-browser: Click location incorrectly checked
bugzilla·2019-08-06·CVSS 4.3
CVE-2019-5861 [MEDIUM] CVE-2019-5861 chromium-browser: Click location incorrectly checked
CVE-2019-5861 chromium-browser: Click location incorrectly checked
The following flaw was identified in the Chromium browser: Click location incorrectly checked.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=951525
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5861
Bugzilla
CVE-2019-5862 chromium-browser: AppCache not robust to compromised renderers
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-5862 [MEDIUM] CVE-2019-5862 chromium-browser: AppCache not robust to compromised renderers
CVE-2019-5862 chromium-browser: AppCache not robust to compromised renderers
The following flaw was identified in the Chromium browser: AppCache not robust to compromised renderers.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=946260
External References:
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:2427 https://access.redhat.com/errata/RHSA-2019:2427
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5862
2019-01-16
Published