Impact
An unauthenticated attacker who can reach Oracle WebLogic Server over standard HTTP can bypass authentication and gain unrestricted access to data exposed by the Web Services component. The vulnerability, classified under CVSS 3.1 with a base score of 8.6, reflects a high confidentiality impact while integrity and availability are not affected. The scope change indicates that the compromise could potentially extend beyond the initial service to other integrated components.
Affected Systems
Oracle WebLogic Server – versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and may be deployed on multiple application platforms.
Risk and Exploitability
The CVSS score of 8.6 places the vulnerability in the High range, and the EPSS score of less than 1% suggests that exploitation instances are currently rare but not impossible. Because the vulnerability is reachable over normal HTTP traffic and requires no authentication, an attacker could mount the exploit from any network that can reach the server without additional credentials. The lack of a KEV listing does not reduce the urgency; the attack surface and the potential impact on confidential data remain significant.
OpenCVE Enrichment