Oracle Webcenter Portal vulnerabilities

90 known vulnerabilities affecting oracle/webcenter_portal.

Total CVEs
90
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL24HIGH49MEDIUM17

Vulnerabilities

Page 5 of 5
CVE-2018-3246HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.02018-10-17
CVE-2018-3246 [HIGH] CVE-2018-3246: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resu
nvd
CVE-2018-3254MEDIUMCVSS 5.3v11.1.1.9.0v12.2.1.3.02018-10-17
CVE-2018-3254 [MEDIUM] CVE-2018-3254: Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: We Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vuln
nvd
CVE-2018-8032MEDIUMCVSS 6.1v12.2.1.3.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-3101MEDIUMCVSS 5.3v11.1.1.9.0v12.2.1.2.0+1 more2018-07-18
CVE-2018-3101 [MEDIUM] CVE-2018-3101: Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: Po Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: Portlet Services). Supported versions that are affected are 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vuln
nvd
CVE-2018-1000613CRITICALCVSS 9.8v11.1.1.9.0v12.2.1.3.02018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2018-1000180HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.02018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2017-15095CRITICALCVSS 9.8v12.2.1.3.02018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvd
CVE-2017-7525CRITICALCVSS 9.8v12.2.1.3.02018-02-06
CVE-2017-7525 [CRITICAL] CWE-184 CVE-2017-7525: A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
nvd
CVE-2018-2713HIGHCVSS 8.2v11.1.1.9.0v12.2.1.2.0+1 more2018-01-18
CVE-2018-2713 [HIGH] CVE-2018-2713: Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: We Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). Supported versions that are affected are 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks re
nvd
CVE-2017-15707MEDIUMCVSS 6.2v12.2.1.2.0v12.2.1.3.02017-12-01
CVE-2017-15707 [MEDIUM] CWE-20 CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulne In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
nvd