Impact
Oracle WebLogic Server is vulnerable in the Console component, allowing a remote attacker with network connectivity over HTTP to gain high privileged access and potentially take control of the server. This flaw is a CWE-284 Improper Access Control vulnerability. The vulnerability demonstrates a CVSS v3.1 base score of 7.2 requires an attacker to send crafted requests to the console interface, after which the attacker can execute arbitrary administrative commands with the server’s privileges.
Affected Systems
Oracle WebLogic Server version 14.1.2.0.0 and 15.1.1.0.0 are affected. These are the only versions specifically listed as vulnerable in the advisory.
Risk and Exploitability
The exploit is access vector of network over HTTP. The EPSS score of less than 1% indicates a very low probability of active exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high-impact CVSS score means that once exploited, an attacker can fully control the target server, compromising all data and services on it. The likely attack path involves a remote HTTP request to the console endpoint that bypasses normal access controls.
OpenCVE Enrichment