Impact
The vulnerability is a critical remote code execution flaw in Oracle WebLogic Server that permits an unauthenticated attacker with network access to compromise the entire server, resulting in full takeover. The flaw leads to complete loss of confidentiality, integrity, and availability due to its ability to run arbitrary code on the affected platform.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected; this includes both standard and fusion middleware deployments of Oracle WebLogic.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates extremely high severity. The EPSS score of less than 1% suggests low overall exploitation probability in the wild, but the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw through unauthenticated network connections to the server via the T3 or IIOP protocols, enabling full remote takeover with no credential or user interaction required.
OpenCVE Enrichment