Impact
Oracle Weblogic Server Proxy Plug‑In for third‑party web servers contains a flaw that allows an unauthenticated attacker to send specially crafted HTTP requests to the plug‑in. The vulnerability permits the attacker to create, delete, or alter data that the plug‑in advertises, thereby compromising the integrity of all data accessible through the plug‑in. The CVSS base score of 9.8, indicating a critical severity vulnerability, reflects the serious integrity impact associated with this flaw. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected Systems
Oracle Products affected include the Oracle HTTP Server and the Oracle Weblogic Server Proxy Plug‑In component of Oracle Fusion Middleware. The vulnerable releases are Oracle HTTP Server 12.2.1.4.0 and 14.1.2.0.0, and Oracle Weblogic Server Proxy Plug‑In 12.2.1.4.0 and 14.1.2.0.0. Any environment that deploys these versions without the vendor’s latest security update is susceptible.
Risk and Exploitability
The CVSS base score is 9.8, indicating a critical severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the attack does not require credentials and only requires HTTP access to the plug‑in endpoint, an active network attacker could readily exercise it if a gateway or load balancer exposes the target. The primary impact is data integrity, and the attack can affect all data reachable through the plug‑in.
OpenCVE Enrichment