Impact
Oracle WebLogic Server is affected by a serious authentication bypass flaw that allows an unauthenticated attacker with network access to the T3 or IIOP ports to execute arbitrary code and gain full control of the managed server. The flaw is classified as a severe vulnerability with a CVSS v3.1 base score of 9.8, indicating complete loss of confidentiality, integrity, and availability. It is rooted in improper authentication checks as documented by the CWE identifiers 287 and 306.
Affected Systems
The flaw impacts specific releases of Oracle WebLogic Server, namely version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The affected products are listed by Oracle as core server components of Fusion Middleware and are exposed through the T3 and IIOP transport protocols.
Risk and Exploitability
Based on the specification, the exploit requires only network connectivity to the vulnerable ports and does not demand user credentials, making it readily usable by attackers with external network presence. While the EPSS score of under 1 % indicates that large‑scale exploitation has not yet been observed, the high CVSS score and the note of the vulnerability being "easily exploitable" warrant attention, especially in environments where the WebLogic server is publicly reachable or poorly segmented. The vulnerability is not currently catalogued in CISA’s Known Exploited Vulnerabilities database, but the potential impact remains severe.
OpenCVE Enrichment