cbcvebase.

Oracle Webcenter Portal vulnerabilities

106 known vulnerabilities affecting oracle/webcenter_portal.

Total CVEs
106
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL39HIGH50MEDIUM17

Vulnerabilities

Page 2 of 6
CVE-2026-46846P2CRITICALCVSS 10.0v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46846 [CRITICAL] CWE-306 CVE-2026-46846: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Securit Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Orac
nvd
CVE-2026-60566P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60566 [CRITICAL] CWE-269 CVE-2026-60566: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerabilit
nvd
CVE-2026-60561P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60561 [CRITICAL] CWE-284 CVE-2026-60561: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle Web
nvd
CVE-2026-60565P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60565 [CRITICAL] CWE-284 CVE-2026-60565: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle Web
nvd
CVE-2026-60562P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60562 [CRITICAL] CWE-284 CVE-2026-60562: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle Web
nvd
CVE-2026-60568P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60568 [CRITICAL] CWE-287 CVE-2026-60568: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle Web
nvd
CVE-2021-21343P3HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21343 [HIGH] CWE-73 CVE-2021-21343: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the proc
nvd
CVE-2018-14718P2CRITICALCVSS 9.8v12.2.1.3.02019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvd
CVE-2026-46802P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46802 [CRITICAL] CWE-284 CVE-2026-46802: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Securit Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracl
nvd
CVE-2026-46767P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46767 [CRITICAL] CWE-284 CVE-2026-46767: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCente
nvd
CVE-2026-46765P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46765 [CRITICAL] CWE-284 CVE-2026-46765: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCente
nvd
CVE-2026-46847P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46847 [CRITICAL] CWE-284 CVE-2026-46847: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle We
nvd
CVE-2026-46838P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46838 [CRITICAL] CWE-284 CVE-2026-46838: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Securit Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Orac
nvd
CVE-2026-46844P2CRITICALCVSS 9.9v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46844 [CRITICAL] CWE-284 CVE-2026-46844: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Securit Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Orac
nvd
CVE-2026-46845P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-46845 [CRITICAL] CWE-306 CVE-2026-46845: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Securit Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal. Successful attacks of this vulner
nvd
CVE-2018-14719P2CRITICALCVSS 9.8v12.2.1.3.02019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2017-15095P2CRITICALCVSS 9.8v12.2.1.3.02018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvd
CVE-2021-39139P2HIGHCVSS 8.8v12.2.1.3.0v12.2.1.4.02021-08-23
CVE-2021-39139 [HIGH] CWE-434 CVE-2021-39139: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario c
nvd
CVE-2026-60564P2CRITICALCVSS 9.6v12.2.1.4.0v14.1.2.0.02026-07-21
CVE-2026-60564 [CRITICAL] CWE-284 CVE-2026-60564: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle Web
nvd
CVE-2021-39154P2HIGHCVSS 8.5v12.2.1.3.0v12.2.1.4.02021-08-23
CVE-2021-39154 [HIGH] CWE-434 CVE-2021-39154: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd