Impact
A vulnerability in Oracle WebLogic Server’s core component allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the server. Successful exploitation can result in full server takeover, leaking or modifying sensitive data and disrupting service availability. The weakness is classified as a high‑impact flaw with a CVSS v3.1 base score of 8.1, indicating that confidentiality, integrity, and availability are all severely affected.
Affected Systems
Oracle Corporation’s WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected by this issue. Any deployment of these releases is susceptible to the described remote takeover vulnerability.
Risk and Exploitability
The vulnerability is difficult to exploit, yet an attacker with network access to the affected services can leverage it without authentication. The EPSS score is reported as less than 1 %, suggesting currently low exploitation probability, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the high CVSS score and the potential for complete server compromise warrant immediate remedial action.
OpenCVE Enrichment