Oracle Webcenter Sites vulnerabilities

53 known vulnerabilities affecting oracle/webcenter_sites.

Total CVEs
53
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH23MEDIUM21LOW2

Vulnerabilities

Page 2 of 3
CVE-2019-2578HIGHCVSS 8.6PoCv12.2.1.3.02019-04-23
CVE-2019-2578 [HIGH] CVE-2019-2578: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may
nvd
CVE-2019-2579MEDIUMCVSS 4.3PoCv12.2.1.3.02019-04-23
CVE-2019-2579 [MEDIUM] CVE-2019-2579: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2019-5427HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoCv12.2.1.3.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2019-0228CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-04-17
CVE-2019-0228 [CRITICAL] CWE-611 CVE-2019-0228: Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent att Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
nvd
CVE-2018-15756HIGHCVSS 7.5v12.2.1.3.02018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2018-3238MEDIUMCVSS 6.9PoCv11.1.1.8.02018-10-17
CVE-2018-3238 [MEDIUM] CVE-2018-3238: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other
nvd
CVE-2018-2791HIGHCVSS 8.2PoCv11.1.1.8.0v12.2.1.2.0+1 more2018-04-19
CVE-2018-2791 [HIGH] CVE-2018-2791: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interac
nvd
CVE-2015-9251MEDIUMCVSS 6.1v11.1.1.8.02018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2018-2584MEDIUMCVSS 4.3v11.1.1.8.02018-01-18
CVE-2018-2584 [MEDIUM] CVE-2018-2584: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2017-10033MEDIUMCVSS 4.0PoCv11.1.1.8.0v12.2.1.2.02017-10-19
CVE-2017-10033 [MEDIUM] CVE-2017-10033: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Sup Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected are 11.1.1.8.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Sites executes to compromise Oracle WebCenter Sites. Su
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoCv11.1.1.8.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-3540HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3540 [HIGH] CVE-2017-3540: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3593HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3593 [HIGH] CVE-2017-3593: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require
nvd
CVE-2017-3602HIGHCVSS 8.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3602 [HIGH] CVE-2017-3602: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3543HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3543 [HIGH] CVE-2017-3543: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3542HIGHCVSS 8.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3542 [HIGH] CVE-2017-3542: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3545HIGHCVSS 8.2v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3545 [HIGH] CVE-2017-3545: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Blo Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Blob Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3596HIGHCVSS 7.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3596 [HIGH] CVE-2017-3596: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3591HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3591 [HIGH] CVE-2017-3591: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Cat Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks requi
nvd