Impact
This vulnerability is caused by missing authentication controls (CWE‑306). A low‑privileged attacker with network access through HTTP can exploit the flaw in the Core component of Oracle WebLogic Server, enabling the attacker to compromise the server and gain full control. The lack of proper authentication leads to confidentiality, integrity, and availability impacts, effectively allowing remote code execution and server takeover.
Affected Systems
Affected by Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of the Fusion Middleware stack and may be deployed in enterprise data centers or cloud environments.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects a high severity. The EPSS score is under 1%, indicating a relatively low probability of current exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is unsecured HTTP traffic accessible over the network; exploitation requires only low‑privilege credentials and can lead to full server compromise.
OpenCVE Enrichment