Impact
The vulnerability permits an attacker who has network access to send SOAP requests to the Oracle WebLogic Server without authentication. By exploiting the flaw, the attacker can execute arbitrary code and gain full control of the server, compromising confidentiality, integrity and availability. The weakness is a form of improper authentication, as indicated by CWE-306.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These releases are part of Oracle Fusion Middleware and rely on the Core component to handle SOAP requests.
Risk and Exploitability
The CVSS score of 9.8 categorises this as a critical vulnerability. The EPSS score of less than 1% suggests abuse is currently unlikely, but the lack of a KEV listing does not diminish the potential impact. Because the flaw traffic over the network, the attack vector is external and relatively easy to craft; the exploit does not require conditions.
OpenCVE Enrichment