Impact
An unauthenticated attacker can use SOAP over the network to execute code and fully take control of Oracle WebLogic Server. The flaw is caused by missing authentication checks before processing SOAP requests, a classic instance of CWE-306. This results in confidentiality, integrity, and availability impacts.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected.
Risk and Exploitability
The CVSS score of 9.8 indicates extreme severity, and the EPSS score of less than 1% suggests a low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. The likely exploitation path involves an unauthenticated network connection to the SOAP service; the flaw can be leveraged to gain any access the WebLogic service itself has, potentially compromising the entire server.
OpenCVE Enrichment