Impact
Vulnerability in the Core component of Oracle WebLogic Server allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the server, potentially leading to full takeover. The flaw enables the attacker to achieve confidentiality, integrity, and availability impacts across the affected system, as indicated by CVSS 3.1 Base Score 8.1.
Affected Systems
It affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The product is part of Oracle Fusion Middleware and is typically deployed in enterprise application environments.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS < 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via the T3 or IIOP ports, and the weakness typifies improper use of a buggy or vulnerable component (CWE-306). Successful exploitation could result in an attacker gaining full control over the WebLogic Server.
OpenCVE Enrichment