Impact
A vulnerability in Oracle WebLogic Server allows an unauthenticated attacker with network connectivity to the T3 or IIOP ports to gain full control of the server. The flaw can be exploited without any prior authentication, and successful exploitation leads to complete takeover of the WebLogic instance, compromising confidentiality, integrity and availability of all data and services running on the server. The issue is a classic remote code execution vulnerability with the potential for widespread system compromise. The underlying issue is a CWE‑306 missing authentication flaw.
Affected Systems
Oracle WebLogic Server from versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 is affected. Any instance of these releases exposed to the public network on the standard T3 or IIOP ports is vulnerable.
Risk and Exploitability
The CVSS v3.1 Base Score of 9.8 indicates a critical impact with high confidence that an attacker can exploit the flaw. The EPSS score of less than 1% is low, indicating that the probability of exploitation is currently low, yet the stock exploitation potential remains high due to the lack of authentication requirement. This vulnerability is not yet listed in the CISA KEV catalog, but the high severity and unauthenticated nature make it a priority target for attackers. The attack vector is inferred to be a network-based remote exploit via T3 or IIOP protocols, requiring no user interaction or credentials.
OpenCVE Enrichment