Impact
This vulnerability in the Oracle WebLogic Server core component allows an unauthenticated attacker with network connectivity to the T3 or IIOP protocols to bypass authentication and gain full control of the server. The flaw can result in the successful compromise of confidentiality, integrity, and availability of all data and services hosted by the affected WebLogic Server installation.
Affected Systems
The affected product is Oracle WebLogic Server across several major releases: version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All instances of these versions running in a networked environment are potentially susceptible.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 signals a critical risk, and the low EPSS score (<1%) indicates that exploitation attempts are currently rare or not widespread. The vulnerability is not listed in CISA KEV, meaning no known mass exploitation has been observed. Based on the description, the most likely attack vector is a direct network connection to the T3 or IIOP port, with no user interaction required. An attacker with remote network access can exploit the flaw to take over the server.
OpenCVE Enrichment