Impact
The vulnerability allows an attacker with low privileges to exploit the WebLogic Server via an HTTP request. Successful exploitation results in unauthorized creation, deletion or modification of critical data, and the ability to cause the server to hang or crash repeatedly. The CVSS v3.1 score of 8.1 reflects high impact on integrity and availability, with no impact on confidentiality.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. The flaw resides in the Core component of Oracle Fusion Middleware.
Risk and Exploitability
The vulnerability is network‑based and exploitable over HTTP with minimal attacker privileges. The EPSS score is < 1%, indicating a low exploitation probability, and the issue is not listed in the CISA KEV catalog, but the high CVSS base score indicates a severe risk. Attackers can target any exposed WebLogic Server instance, potentially compromising data integrity and causing service outages. The exploit does not require authentication, making it accessible to low‑privileged or unauthenticated users with network reach.
OpenCVE Enrichment