Impact
The vulnerability resides in the Core component of Oracle WebLogic Server and is a CWE-306 authentication bypass that allows an unauthenticated attacker with network access via HTTP to compromise the server. Successful exploitation enables arbitrary code execution, resulting in full control of the host and loss of confidentiality, integrity and availability.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are expressly affected and are widely deployed in enterprise environments.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity with a network attack vector and no authentication required. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is an unauthenticated HTTP request that bypasses authentication checks in the Core component, leading to full server takeover. Defenses include patching and tightening network access.
OpenCVE Enrichment