Oracle Webcenter Portal vulnerabilities
106 known vulnerabilities affecting oracle/webcenter_portal.
Total CVEs
106
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL39HIGH50MEDIUM17
Vulnerabilities
Page 6 of 6
CVE-2019-12415P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2021-41165P4MEDIUMCVSS 5.4v12.2.1.3.0v12.2.1.4.02021-11-17
CVE-2021-41165 [MEDIUM] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usi
nvd
CVE-2021-41164P4MEDIUMCVSS 5.4v12.2.1.3.0v12.2.1.4.02021-11-17
CVE-2021-41164 [MEDIUM] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users us
nvd
CVE-2021-28657P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02021-03-31
CVE-2021-28657 [MEDIUM] CWE-835 CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and inclu
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
nvd
CVE-2020-9489P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02020-04-27
CVE-2020-9489 [MEDIUM] CWE-835 CVE-2020-9489: A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or c
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser
nvd
CVE-2024-20992P4MEDIUMCVSS 4.4v12.2.1.4.02024-04-16
CVE-2024-20992 [MEDIUM] CWE-284 CVE-2024-20992: Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction fro
nvd
← Previous6 / 6