Oracle Webcenter Sites vulnerabilities
54 known vulnerabilities affecting oracle/webcenter_sites.
Total CVEs
54
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH23MEDIUM21LOW2
Vulnerabilities
Page 1 of 3
CVE-2017-12617P1HIGHCVSS 8.1KEVPoCv11.1.1.8.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCv12.2.1.3.0v12.2.1.4.02020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev12.2.1.3.0v12.2.1.4.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv12.2.1.3.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2015-9251P2MEDIUMCVSS 6.1ExploitedPoCv11.1.1.8.02018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2021-29505P1HIGHCVSS 8.8PoCv12.2.1.3.0v12.2.1.4.02021-05-28
CVE-2021-29505 [HIGH] CWE-94 CVE-2021-29505: XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream v
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limi
nvd
CVE-2019-2578P2HIGHCVSS 8.6PoCv12.2.1.3.02019-04-23
CVE-2019-2578 [HIGH] CVE-2019-2578: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may
nvd
CVE-2018-2791P2HIGHCVSS 8.2PoCv11.1.1.8.0v12.2.1.2.0+1 more2018-04-19
CVE-2018-2791 [HIGH] CVE-2018-2791: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interac
nvd
CVE-2015-3253P2CRITICALCVSS 9.8v11.1.1.8.0v12.2.12015-08-13
CVE-2015-3253 [CRITICAL] CWE-74 CVE-2015-3253: The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows re
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
nvd
CVE-2026-61140P2CRITICALCVSS 9.8v14.1.2.0.02026-07-21
CVE-2026-61140 [CRITICAL] CWE-284 CVE-2026-61140: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCente
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result i
nvd
CVE-2018-3238P3MEDIUMCVSS 6.9PoCv11.1.1.8.02018-10-17
CVE-2018-3238 [MEDIUM] CVE-2018-3238: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other
nvd
CVE-2019-16942P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvd
CVE-2019-17531P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-12
CVE-2019-17531 [CRITICAL] CWE-502 CVE-2019-17531: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it i
nvd
CVE-2019-16943P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-01
CVE-2019-16943 [CRITICAL] CWE-502 CVE-2019-16943: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to m
nvd
CVE-2019-13990P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2014-0107P3HIGHCVSS 7.5v7.6.2v11.1.1.8.02014-04-15
CVE-2014-0107 [HIGH] CWE-264 CVE-2014-0107: The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certai
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-head
nvd
CVE-2019-0228P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-04-17
CVE-2019-0228 [CRITICAL] CWE-611 CVE-2019-0228: Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent att
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
nvd
CVE-2017-3543P3HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3543 [HIGH] CVE-2017-3543: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3542P3HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3542 [HIGH] CVE-2017-3542: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3540P3HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3540 [HIGH] CVE-2017-3540: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
1 / 3Next →