Impact
This vulnerability in Oracle WebLogic Server’s Core component can be triggered by unauthenticated adversaries who have network reach to the T3 or IIOP interfaces. Once exploited the attacker gains full control of the server, compromising confidentiality, integrity, and availability. The CVSS v3.1 base score of 8.1 indicates a high-impact attack that can lead to a total system takeover.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. These versions include the Core component susceptible to this flaw.
Risk and Exploitability
The vulnerability is difficult to exploit but has a high CVSS score, meaning significant potential damage if successful. EPSS data is unavailable, so the likelihood of exploitation is not quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the vulnerable protocols, with no user interaction required; once the flaw is triggered, the server can be fully compromised.
OpenCVE Enrichment