Impact
The vulnerability is an authentication bypass in Oracle WebLogic Server that permits an unauthenticated attacker to gain full control of the server via HTTP. An attacker can compromise confidentiality, integrity, and availability by taking over the server, allowing arbitrary code execution and full data compromise. The weakness is associated with improper authentication safeguards and missing access control checks, resulting in a severe threat to systems that rely on WebLogic for application deployment.
Affected Systems
Vendor and product: Oracle WebLogic Server. Affected releases are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Other Oracle Fusion Middleware products may be impacted as the vulnerability has a scope change that could affect additional components.
Risk and Exploitability
The CVSS base score is 10.0, indicating critical severity. The EPSS score is less than 1%, suggesting a low likelihood of current exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. However, the attack vector is local network via HTTP, and because authentication is bypassed, any workstation with network access can launch the attack. Successful exploitation leads to total server takeover, underscoring the high risk even if real-world exploitation may be small at present.
OpenCVE Enrichment