Impact
Oracle WebLogic Server is vulnerable to an unauthenticated remote code execution flaw that allows attackers to bypass authentication via the T3 and IIOP protocols. The weakness stems from improper authentication checks (CWE‑287) and weak credential handling (CWE‑306). Successful exploitation can result in full takeover of the server, compromising confidentiality, integrity, and availability of all hosted applications.
Affected Systems
The affected products are Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Administrators should verify that their deployments are running these revisions and assess the potential impact on production and staging environments.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 reflects a highly severe risk, with network access required and low attack complexity. Although the EPSS score is reported as less than 1 %, indicating a very low current exploitation likelihood, the flaw is not yet listed in the CISA KEV catalog. An attacker with network connectivity to the T3 or IIOP ports can readily exploit this vulnerability without authentication, leading to immediate compromise of the WebLogic Server.
OpenCVE Enrichment