Impact
This vulnerability is an unauthenticated flaw in the Remote Method Invocation (RMI) component of Oracle WebLogic Server. An attacker who can reach the server over the network may exploit insufficient access control (CWE-284) to invoke privileged APIs, allowing remote execution of arbitrary code and eventual complete takeover. The flaw directly impacts confidentiality, integrity, and availability, as the attacker can read, modify, or delete data and disrupt the server’s operation.
Affected Systems
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 are affected. The issue is present in the WebLogic Server core components and is applicable to deployments that expose the RMI port over the network.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical severity, and the attack vector is network-based, requiring only open RMI access and no authentication. The EPSS score is less than 1% (approximately 0.00549), indicating a very low exploit probability, but the lack of authentication and the ability to execute arbitrary code still make this a high‑risk vulnerability. The vulnerability is not listed in CISA’s KEV catalog, yet the high score and known exploitation potential warrant immediate attention.
OpenCVE Enrichment