Impact
This vulnerability in Oracle WebLogic Server’s Core component allows an unauthenticated attacker with network access through the T3 or IIOP protocols to compromise the server. A successful exploit results in full server takeover, exposing confidential data, altering or deleting system files, and disrupting service availability. The weakness, classified as CWE-200, is rated with a CVSS v3.1 base score of 8.1, reflecting significant impacts to confidentiality, integrity and availability.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These releases include the Core component that is vulnerable to this flaw.
Risk and Exploitability
The exploit is difficult, but the issue carries a high CVSS score, signaling severe potential damage if successful. The EPSS score of less than 1 % indicates a low probability of exploitation in the current threat landscape. Attackers require network connectivity to the vulnerable T3 or IIOP ports and do not need user interaction; once the flaw is triggered, the server can be fully compromised. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment