Impact
The vulnerability is an authentication bypass in Oracle WebLogic Server that allows an attacker to send specially crafted T3 or IIOP traffic and gain unauthorized control of the server. Once exploited the attacker can fully compromise the server, achieving impacts on confidentiality, integrity, and availability. The weakness is identified as improper authentication and missing authentication for a critical function.
Affected Systems
This issue affects Oracle WebLogic Server across several major releases, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. All installations running these versions are potentially vulnerable if exposed to the network.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 signals a critical severity, but the EPSS score is below 1%, indicating that current exploitation trends are very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network reachability to the vulnerable service ports; no user interaction or privileged console is needed. Attackers could leverage the open T3 or IIOP interfaces on typically accessible ports to trigger the flaw and achieve remote code execution.
OpenCVE Enrichment