Impact
An improper access control flaw in Oracle WebLogic Server allows an attacker with high privileges who can access the physical communication segment to take full control of the server. The weakness lets the attacker bypass normal authorization checks, compromising confidentiality, integrity, and availability for all applications. Based on the description, it is inferred that the attacker must have physical or local network access to the server’s hardware or supporting infrastructure to execute the exploit.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of the Oracle Fusion Middleware product family.
Risk and Exploitability
The CVSS 3.1 base score of 8.4 indicates a high severity vulnerability with confidentiality, integrity, and availability impacts. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the likely attack vector is local network access on the same physical segment, possibly through exposed management ports. Successful exploitation can result in total takeover of the WebLogic Server.
OpenCVE Enrichment