Impact
A flaw in the core component of Oracle WebLogic Server arises from an absence of proper authentication controls for certain privileged operations. The vulnerability enables a low‑privileged attacker with network access over HTTP to trigger code execution paths that bypass expected authorization checks, leading to full compromise of the server. The described impact touches all confidentiality, integrity, and availability aspects, allowing the attacker to execute arbitrary code and seize control of the WebLogic installation.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0, used as part of Oracle Fusion Middleware, are affected by this issue.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high severity risk, while the EPSS score of less than 1 % suggests the current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP, requiring only low privileges to trigger the exploit and attain full server takeover. The missing authentication requirement is inferred from the CVSS vector and the description of the attacker’s low privilege level.
OpenCVE Enrichment