Description
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Weblogic Server Proxy Plug‑In for third‑party web servers contains a flaw that allows an unauthenticated attacker to send specially crafted HTTP requests to the plug‑in. The vulnerability permits the attacker to create, delete, or alter data that the plug‑in advertises, thereby compromising the integrity of all data accessible through the plug‑in. The CVSS base score of 9.8, indicating a critical severity vulnerability, reflects the serious integrity impact associated with this flaw. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Affected Systems

Oracle Products affected include the Oracle HTTP Server and the Oracle Weblogic Server Proxy Plug‑In component of Oracle Fusion Middleware. The vulnerable releases are Oracle HTTP Server 12.2.1.4.0 and 14.1.2.0.0, and Oracle Weblogic Server Proxy Plug‑In 12.2.1.4.0 and 14.1.2.0.0. Any environment that deploys these versions without the vendor’s latest security update is susceptible.

Risk and Exploitability

The CVSS base score is 9.8, indicating a critical severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the attack does not require credentials and only requires HTTP access to the plug‑in endpoint, an active network attacker could readily exercise it if a gateway or load balancer exposes the target. The primary impact is data integrity, and the attack can affect all data reachable through the plug‑in.

Generated by OpenCVE AI on August 4, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle HTTP Server to a patched release that includes the vendor‑supplied fix for versions 12.2.1.4.0 or later, and upgrade Oracle Weblogic Server Proxy Plug‑In to the corresponding patched release 12.2.1.4.0 or later.
  • Remove or disable the Weblogic Server Proxy Plug‑In component if it is not required for your application.
  • Restrict HTTP access to the plug‑in interface so that only trusted IP addresses or authenticated clients can reach it.
  • Enable authentication for the plug‑in, if the configuration allows, and enforce strong credentials.

Generated by OpenCVE AI on August 4, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Enables Integrity Compromise in Oracle Weblogic Server Proxy Plug‑In

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle Weblogic Proxy Plug‑In

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle Weblogic Proxy Plug‑In
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle http Server
Oracle weblogic Server Proxy Plug-in
CPEs cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
Oracle weblogic Server Proxy Plug-in
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Http Server Weblogic Server Proxy Plug-in
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:47.494Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60364

cve-icon Vulnrichment

Updated: 2026-07-24T17:04:34.499Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses