Impact
The vulnerability allows an attacker who has low privileges and network access to an Oracle WebLogic Server through the Remote Method Invocation (RMI) interface to compromise the server, resulting in full takeover. The exploit is classified as easily exploitable and can lead to loss of confidentiality, integrity, and availability of the affected service, allowing the attacker to execute arbitrary code and control the server. The weakness involves improper handling of privileged calls within the Core component, exposing the system to arbitrary code execution.
Affected Systems
Affected vendor Oracle WebLogic Server versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Systems running any of these versions are vulnerable and may be exposed if the RMI interface is reachable from the network.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high severity exploit with low complexity and low privileges required. The EPSS score of less than 1% signals a low probability of current exploitation observed, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the likely attack vector is a remote network-based attack leveraging the RMI port; an attacker only needs to send a crafted request to the RMI service to trigger the code execution path.
OpenCVE Enrichment