Impact
The flaw in Oracle WebLogic Server allows an unauthenticated attacker with network access via TCP to fully compromise the server. The weakness is a credential‑less authentication bypass, identified as CWE‑306, which permits remote code execution, impacting confidentiality, integrity, and availability. Successful exploitation can result in a complete takeover of the WebLogic instance.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0 are affected, with the core component of Oracle Fusion Middleware serving as the entry point for exploitation.
Risk and Exploitability
The CVSS base score of 9.8 signals a critical impact. The EPSS score of less than 1% indicates a low current exploitation prevalence, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is a remote network connection over TCP to exposed WebLogic ports, enabling an attacker to use the unauthenticated weakness to gain full control of the server.
OpenCVE Enrichment