Impact
Oracle WebLogic Server is vulnerable to an unauthenticated remote code execution flaw that allows attackers to bypass authentication via the T3 and IIOP protocols. The weakness is rooted in improper authentication checks (CWE-287) and weak credential handling (CWE-306). Successful exploitation can lead to full takeover of the server, compromising confidentiality, integrity, and availability of all hosted applications.
Affected Systems
Affected versions are Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Administrators should verify their deployments against these revisions and consider the impact on production and staging environments.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 reflects a highly severe risk, with network access required and low attack complexity. Although the EPSS score is reported as less than 1 %, indicating a very low current exploitation likelihood, the vulnerability is listed as not yet in the CISA KEV catalog. An attacker with network connectivity to the T3 or IIOP ports can readily exploit this flaw without authentication, leading to immediate compromise of the WebLogic Server.
OpenCVE Enrichment