cbcvebase.

Oracle Webcenter Sites vulnerabilities

54 known vulnerabilities affecting oracle/webcenter_sites.

Total CVEs
54
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH23MEDIUM21LOW2

Vulnerabilities

Page 3 of 3
CVE-2021-26272P4MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.02021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2016-3502P4MEDIUMCVSS 6.5v11.1.1.8v12.2.1.02016-07-21
CVE-2016-3502 [MEDIUM] CVE-2016-3502: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 11.1.1.8 and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2021-26271P4MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.02021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2020-14613P4MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02020-07-15
CVE-2020-14613 [MEDIUM] CWE-79 CVE-2020-14613: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced User Interface). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human i
nvd
CVE-2024-20908P4MEDIUMCVSS 6.1v12.2.1.4.02024-01-16
CVE-2024-20908 [MEDIUM] CVE-2024-20908: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other th
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2020-2539P4MEDIUMCVSS 6.1v12.2.1.3.02020-01-15
CVE-2020-2539 [MEDIUM] CVE-2020-2539: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4v12.2.1.3.0v12.2.1.4.02021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2021-27906P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27807P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2016-5511P4MEDIUMCVSS 4.3v12.2.1.0.0v12.2.1.1.0+1 more2016-10-25
CVE-2016-5511 [MEDIUM] CWE-254 CVE-2016-5511: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2018-2584P4MEDIUMCVSS 4.3v11.1.1.8.02018-01-18
CVE-2018-2584 [MEDIUM] CVE-2018-2584: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2017-3598P4LOWCVSS 3.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3598 [LOW] CVE-2017-3598: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this v
nvd
CVE-2017-3603P4LOWCVSS 3.1v11.1.1.8.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3603 [LOW] CVE-2017-3603: Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Adv Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this v
nvd
Oracle Webcenter Sites vulnerabilities | cvebase