Impact
This vulnerability in Oracle WebLogic Server permits an attacker with low privileges to gain full control of the server when the attacker can reach the T3 or IIOP interfaces over the network. Because the exploit requires only basic network connectivity and does not need user interaction, it is considered easily exploitable. The CVSS 3.1 base score of 9.9 reflects complete confidentiality, integrity, and availability impacts.
Affected Systems
Affected versions are Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw’s impact spans a scope change, meaning that compromise of the WebLogic instance could propagate to other applications or services running on the same host or virtual environment, extending the damage beyond the initial target. Network protocols required for exploitation are T3 and IIOP, providing a fixed entry point for attackers who can reach the server.
Risk and Exploitability
The risk is high because the CVSS score of 9.9 signals critical severity, and the EPSS score is reported as less than 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not yet listed in CISA’s KEV catalog, but the remote nature of the attack and the potential to affect additional products suggests that it should be treated with urgency. Successful exploitation results in an attacker assuming the same privileges as the WebLogic process, giving full control over the server and any deployed applications.
OpenCVE Enrichment