Impact
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, specifically the TopLink Integration component, permits a low‑privileged attacker who can reach the server over HTTP to compromise the server. Successful exploitation can result in a full takeover, giving the attacker control over confidentiality, integrity, and availability. The flaw is classified under CWE‑284 and is reflected in a CVSS v3.1 base score of 9.9, indicating a critical impact.
Affected Systems
The affected product is Oracle WebLogic Server. Vulnerable releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of the Oracle Fusion Middleware stack and are still supported at the time of the advisory. The TopLink Integration component is the point of entry for the vulnerability.
Risk and Exploitability
The CVSS score of 9.9 underscores a critical severity, while an EPSS score of less than 1% suggests that exploitation is currently rare but not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based request to the WebLogic Server over HTTP; authentication is not required, and the attacker needs only low privileges, as indicated by the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
OpenCVE Enrichment