Home/Product/oracle webcenter portal
Product

oracle webcenter portal

90 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-20992
all versions
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The supported
4.4MEDIUM
CVE-2021-45105
all versions
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from sel
5.9MEDIUM
CVE-2021-41165
all versions
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processi
8.2HIGH
CVE-2021-41164
all versions
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content
8.2HIGH
CVE-2021-37137
all versions
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also
7.5HIGH
CVE-2021-37136
all versions
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects th
7.5HIGH
CVE-2021-39152
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39150
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39140
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
6.5MEDIUM
CVE-2021-39154
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39153
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39151
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39149
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39148
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39147
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39146
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39145
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39144
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39141
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-39139
all versions
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5HIGH
CVE-2021-37714
all versions
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vu
7.5HIGH
CVE-2021-36090
all versions
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35517
all versions
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35516
all versions
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out
7.5HIGH
CVE-2021-29505
all versions
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may al
7.5HIGH
CVE-2021-29425
all versions
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo",
4.8MEDIUM
CVE-2021-28657
all versions
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika us
5.5MEDIUM
CVE-2021-21351
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability m
5.4MEDIUM
CVE-2021-21350
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21349
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21348
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21347
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21346
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1MEDIUM
CVE-2021-21345
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.8MEDIUM
CVE-2021-21344
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21343
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21342
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3MEDIUM
CVE-2021-21341
all versions
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability whi
7.5HIGH
CVE-2020-36183
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36182
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36180
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36179
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oad
8.1HIGH
CVE-2020-36189
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36188
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36187
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36186
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36185
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36184
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36181
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-35728
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-28052
all versions
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compa
8.1HIGH
CVE-2020-35491
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-35490
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-25649
all versions
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerab
7.5HIGH
CVE-2020-14611
all versions
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that ar
8.6HIGH
CVE-2020-14552
all versions
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versio
6.8MEDIUM
CVE-2020-10683
all versions
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. H
9.8CRITICAL
CVE-2020-9489
all versions
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause
5.5MEDIUM
CVE-2020-11612
all versions
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An a
7.5HIGH
CVE-2020-11113
all versions
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-9281
all versions
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inje
6.1MEDIUM
CVE-2020-2555
all versions
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported ve
9.8CRITICAL
CVE-2019-20330
all versions
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
9.8CRITICAL
CVE-2019-10219
all versions
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting
6.1MEDIUM
CVE-2019-12415
all versions
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially cra
5.5MEDIUM
CVE-2019-17531
all versions
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (eith
9.8CRITICAL
CVE-2019-17359
all versions
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMe
7.5HIGH
CVE-2019-16943
all versions
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (eith
9.8CRITICAL
CVE-2019-16942
all versions
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (eith
9.8CRITICAL
CVE-2019-12402
all versions
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced
7.5HIGH
CVE-2019-10173
all versions
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the sec
9.8CRITICAL
CVE-2019-0227
all versions
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Secur
7.5HIGH
CVE-2019-2427
all versions
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). S
5.3MEDIUM
CVE-2018-19362
all versions
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jb
9.8CRITICAL
CVE-2018-19361
all versions
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the op
9.8CRITICAL
CVE-2018-19360
all versions
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the ax
9.8CRITICAL
CVE-2018-14721
all versions
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by
10.0CRITICAL
CVE-2018-14720
all versions
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failu
9.8CRITICAL
CVE-2018-14719
all versions
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block
9.8CRITICAL
CVE-2018-14718
all versions
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block
9.8CRITICAL
CVE-2018-3254
all versions
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). S
5.3MEDIUM
CVE-2018-3246
all versions
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported ve
7.5HIGH
CVE-2018-8032
all versions
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
6.1MEDIUM
CVE-2018-3101
all versions
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: Portlet Services). Supported ver
5.3MEDIUM
CVE-2018-1000613
all versions
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-47
9.8CRITICAL
CVE-2018-1000180
all versions
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair genera
7.5HIGH
CVE-2017-7525
all versions
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an un
9.8CRITICAL
CVE-2017-15095
all versions
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenti
9.8CRITICAL
CVE-2018-2713
all versions
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Application). S
8.2HIGH
CVE-2017-15707
all versions
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS
6.2MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin