Impact
The vulnerability allows an unauthenticated attacker who can reach the server over HTTP to create, delete, or modify critical data in Oracle WebLogic Server. The attacker can also obtain unauthorized read access to all data that the server exposes. The impact is limited to confidentiality and integrity, with no availability loss. According to the CVSS vector, the flaw is high severity with a base score of 9.1.
Affected Systems
Oracle WebLogic Server releases 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are documented as affected. Any installation of one of these versions that is reachable via HTTP is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. The EPSS score of less than 1% signals a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network-based with no authentication or user interaction required, meaning an attacker with network access to the WebLogic Server could exploit the flaw by sending a crafted HTTP request.
OpenCVE Enrichment