Impact
A vulnerability in Oracle WebLogic Server allows a low‑privileged attacker with network access to HTTP to execute arbitrary code, resulting in takeover of the entire server. The CVSS V3.1 score of 8.8 indicates high severity with confidentiality, integrity and availability impacts. The flaw is consistent with improper access control or authentication weaknesses, which enable an attacker to bypass normal security checks and gain unrestricted control.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, part of Oracle Fusion Middleware’s Core component, are affected. The vulnerability applies to the HTTP management interface exposed by these releases.
Risk and Exploitability
The EPSS score of less than 1% implies exploit potential is currently low, yet the high CVSS score and lack of CISA KEV listing mean the risk remains significant. The likely attack vector is over the network using HTTP requests; an attacker requires only network connectivity to the WebLogic port and can exploit the flaw without additional privileges. Successful exploitation could compromise all data and services hosted on the affected server.
OpenCVE Enrichment