Impact
Unauthenticated attackers can exploit Oracle WebLogic Server via the T3 or IIOP protocols to gain full control of the system. The flaw allows an attacker to take over the WebLogic instance, resulting in complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.8 underscores the severity of the vulnerability, indicating that no privileges are required for exploitation.
Affected Systems
Oracle WebLogic Server is impacted. All supported releases listed as affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are widely deployed in enterprise environments and include the core components necessary for the exploitation described.
Risk and Exploitability
The vulnerability is network reachable via the T3 and IIOP interfaces and requires no authentication, making the attack surface very broad. With a CVSS score of 9.8 and an EPSS score of < 1%, the exploitation probability remains low, yet the severity of compromise is extremely high. The vulnerability is not yet listed in the CISA KEV catalog, but the severity and exposure suggest a high priority for remediation.
OpenCVE Enrichment