Impact
Oracle WebLogic Server is vulnerable to a flaw that allows an unauthenticated attacker who can reach the server over HTTP to execute code on the host. The weakness stems from missing authentication for a critical function (CWE‑306) and can result in a complete takeover of the WebLogic Server, compromising confidentiality, integrity, and availability of any applications or data it hosts.
Affected Systems
The affected product is Oracle WebLogic Server, part of Oracle Fusion Middleware. The vulnerable Core component is present in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates a critical severity, while the EPSS score of < 1 % shows that the likelihood of exploitation at this time is low. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests to a vulnerable WebLogic Server instance over the network, without needing authentication, potentially leading to full system compromise.
OpenCVE Enrichment