Impact
A flaw in Oracle WebLogic Server enables an attacker to control the server without authenticating, using standard HTTP traffic. Once exploited, the attacker can read, modify, or delete data, and even run arbitrary code, effectively taking over the application environment. The vulnerability is identified as a high‑severity flaw with a CVSS 3.1 score of 9.8, indicating full confidentiality, integrity, and availability compromise for any vulnerable instance.
Affected Systems
Oracle Corporation’s WebLogic Server, specifically versions 12.2.1.4.0 and 14.1.1.0.0, are affected. These versions are part of Oracle Fusion Middleware’s Core component. No additional vendor or product variants are listed as impacted.
Risk and Exploitability
The attack vector is likely through normal network exposure: an unauthenticated user can send request via HTTP to the server and trigger the flaw. The CVSS score reflects that the exploit is easy and can be performed remotely without prior access or special credentials. The EPSS score is reported as <1%, implying that the probability of exploitation at any given moment is low, but the high severity and lack of proof of concepts in public advisories mean that a discovered vulnerability could be leveraged by a determined adversary. The vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known active attacks yet, but its potential consequences warrant immediate attention.
OpenCVE Enrichment