Impact
The vulnerability resides in the Oracle WebLogic Server Proxy Plug‑in component for third‑party web servers, enabling an unauthenticated attacker with network access via HTTP to compromise the plug‑in. Successful exploitation allows the attacker to create, delete, or modify critical data, or gain full unauthorized access to all proxied data, severely impacting confidentiality and integrity.
Affected Systems
This issue affects Oracle WebLogic Server Proxy Plug‑in version 15.1.1.0.0. Oracle HTTP Server release 12.2.1.4.0 and 14.1.2.0.0 are also listed as affected via the provided CPE entries, though the description specifically references the Proxy Plug‑in. Users should verify whether their installations match these vulnerable versions.
Risk and Exploitability
The CVSS score of 10.0 underscores critical severity, while an EPSS of <1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires only network access to exposed HTTP interfaces, without authentication, meaning any host that can reach the plug‑in could attempt the exploit. The scope change noted in the description hints at potential privilege escalation, making this a highly risky flaw despite its low exploitation likelihood.
OpenCVE Enrichment