Impact
A vulnerability exists in the WebLogic Server Console component that allows an attacker who can access the server over HTTPS to gain high privileged control. The flaw is sufficient to enable a full takeover of the Oracle WebLogic Server, resulting in loss of all confidentiality, integrity, and availability for the affected instance. The weakness is classified as CWE-306, indicating missing authentication for a sensitive function.
Affected Systems
Oracle Corporation’s WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are delivered as part of Oracle Fusion Middleware and use the Console for administrative operations.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 denotes high severity with full CIA impact. The EPSS score of less than 1% indicates that, while exploitation is feasible, it is rarely observed in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring network access to the HTTPS console endpoint and a high privilege level on the target system.
OpenCVE Enrichment