cbcvebase.

Oracle Webcenter Sites vulnerabilities

54 known vulnerabilities affecting oracle/webcenter_sites.

Total CVEs
54
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH23MEDIUM21LOW2

Vulnerabilities

Page 2 of 3
CVE-2017-3541P3HIGHCVSS 8.2v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3541 [HIGH] CVE-2017-3541: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2019-2579P4MEDIUMCVSS 4.3PoCv12.2.1.3.02019-04-23
CVE-2019-2579 [MEDIUM] CVE-2019-2579: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2017-3545P3HIGHCVSS 8.2v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3545 [HIGH] CVE-2017-3545: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Blo Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Blob Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3602P3HIGHCVSS 8.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3602 [HIGH] CVE-2017-3602: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3554P3HIGHCVSS 8.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3554 [HIGH] CVE-2017-3554: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Cat Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of thi
nvd
CVE-2016-3487P3HIGHCVSS 8.1v11.1.1.8v12.2.1.02016-07-21
CVE-2016-3487 [HIGH] CVE-2016-3487: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1.8, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2018-15756P3HIGHCVSS 7.5v12.2.1.3.02018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2017-3596P3HIGHCVSS 7.6v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3596 [HIGH] CVE-2017-3596: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-10033P4MEDIUMCVSS 4.0PoCv11.1.1.8.0v12.2.1.2.02017-10-19
CVE-2017-10033 [MEDIUM] CVE-2017-10033: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Sup Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected are 11.1.1.8.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Sites executes to compromise Oracle WebCenter Sites. Su
nvd
CVE-2020-5258P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02020-03-10
CVE-2020-5258 [HIGH] CWE-94 CVE-2020-5258: In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the ba
nvd
CVE-2013-4316P3CRITICALCVSS 10.0v11.1.1.6.1v11.1.1.8.02013-09-30
CVE-2013-4316 [CRITICAL] CWE-16 CVE-2013-4316: Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
nvd
CVE-2019-5427P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2017-3595P3HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3595 [HIGH] CVE-2017-3595: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2020-2739P3HIGHCVSS 7.4v12.2.1.3.02020-04-15
CVE-2020-2739 [HIGH] CVE-2020-2739: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than t
nvd
CVE-2020-7226P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02020-01-24
CVE-2020-7226 [HIGH] CWE-770 CVE-2020-7226: CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attacke CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
nvd
CVE-2017-3593P3HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3593 [HIGH] CVE-2017-3593: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require
nvd
CVE-2017-3591P3HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3591 [HIGH] CVE-2017-3591: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Cat Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks requi
nvd
CVE-2017-3594P3MEDIUMCVSS 5.9v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3594 [MEDIUM] CVE-2017-3594: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of thi
nvd
CVE-2017-3597P4MEDIUMCVSS 5.7v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3597 [MEDIUM] CVE-2017-3597: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks requir
nvd
CVE-2020-2538P4HIGHCVSS 7.1v12.2.1.3.02020-01-15
CVE-2020-2538 [HIGH] CVE-2020-2538: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than t
nvd
Oracle Webcenter Sites vulnerabilities | cvebase