Impact
Oracle WebLogic Server’s Console component has an authorization flaw that lets a high‑privileged attacker with network access over HTTP create, delete, or modify data in the server and, in some cases, read other data. The vulnerability permits unauthorized administrative changes that can compromise confidentiality and integrity of critical information.
Affected Systems
Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 are vulnerable when the administrative console is exposed over HTTP.
Risk and Exploitability
The CVSS base score of 7.6 indicates high severity, yet the EPSS score of less than 1% shows a low probability of exploitation currently. Attackers would use the console over HTTP to gain elevated privileges, potentially affecting other applications that rely on the same WebLogic instance. Although the flaw is not listed in CISA’s KEV catalog, its severity warrants the same level of attention as any CVSS 7.6 vulnerability.
OpenCVE Enrichment