Impact
This vulnerability, a CWE-284 Weakness in the Oracle WebLogic Server console component, allows an unauthenticated attacker with local system access to read protected configuration data. It does not provide arbitrary code execution, but the compromised data can include credentials, debugging information, and other highly confidential information. Because the flaw changes the scope, a successful exploitation may also enable the attacker to access other applications that run on the same WebLogic instance, extending the confidentiality impact beyond the original console service.
Affected Systems
Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 are affected, specifically the console module of these releases.
Risk and Exploitability
The CVSS Base score of 7.1 indicates high severity, with low attack complexity, no privileges required, and no user interaction. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local: the attacker must already have access to the infrastructure where WebLogic is running. From that position, the console flaw can be used to read protected data, and the scope change can extend access to other components that share the same WebLogic instance.
OpenCVE Enrichment