Oracle Webcenter Sites vulnerabilities

53 known vulnerabilities affecting oracle/webcenter_sites.

Total CVEs
53
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH23MEDIUM21LOW2

Vulnerabilities

Page 3 of 3
CVE-2017-3541HIGHCVSS 8.2v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3541 [HIGH] CVE-2017-3541: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vuln
nvd
CVE-2017-3595HIGHCVSS 7.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3595 [HIGH] CVE-2017-3595: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this
nvd
CVE-2017-3554HIGHCVSS 8.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3554 [HIGH] CVE-2017-3554: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Cat Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of thi
nvd
CVE-2017-3594MEDIUMCVSS 5.9v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3594 [MEDIUM] CVE-2017-3594: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of thi
nvd
CVE-2017-3597MEDIUMCVSS 5.7v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3597 [MEDIUM] CVE-2017-3597: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks requir
nvd
CVE-2017-3598LOWCVSS 3.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3598 [LOW] CVE-2017-3598: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this v
nvd
CVE-2017-3603LOWCVSS 3.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3603 [LOW] CVE-2017-3603: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this v
nvd
CVE-2016-5511MEDIUMCVSS 4.3v12.2.1.0.0v12.2.1.1.0+1 more2016-10-25
CVE-2016-5511 [MEDIUM] CWE-254 CVE-2016-5511: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2016-3487HIGHCVSS 8.1v11.1.1.8v12.2.1.02016-07-21
CVE-2016-3487 [HIGH] CVE-2016-3487: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1.8, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-3502MEDIUMCVSS 6.5v11.1.1.8v12.2.1.02016-07-21
CVE-2016-3502 [MEDIUM] CVE-2016-3502: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1.8 and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-3253CRITICALCVSS 9.8v11.1.1.8.0v12.2.12015-08-13
CVE-2015-3253 [CRITICAL] CWE-74 CVE-2015-3253: The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows re The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
nvd
CVE-2014-0107HIGHCVSS 7.5v7.6.2v11.1.1.8.02014-04-15
CVE-2014-0107 [HIGH] CWE-264 CVE-2014-0107: The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certai The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-head
nvd
CVE-2013-4316CRITICALCVSS 10.0v11.1.1.6.1v11.1.1.8.02013-09-30
CVE-2013-4316 [CRITICAL] CWE-16 CVE-2013-4316: Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
nvd
Oracle Webcenter Sites vulnerabilities | cvebase