Impact
The flaw is a missing authentication or authorization check in the core component of Oracle WebLogic Server, identified as CWE‑306. It allows a low‑privileged attacker with network reach to exploit the server through SAML authentication. Successful exploitation results in complete takeover of the server, compromising confidentiality, integrity and availability, and potentially affecting other products that depend on WebLogic.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are impacted. These versions are part of Oracle Fusion Middleware and are frequently deployed in enterprise environments.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates critical severity. The EPSS score of <1% suggests a very low current probability of exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the vulnerability can be triggered remotely over the network, requires only low privileges, and grants full control of the server, enabling data exfiltration, service disruption, or lateral movement.
OpenCVE Enrichment