Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOracle Agile Product Lifecycle Management
APPOracle9.3.39.3.49.3.5Oracle Communications Converged Application Server
APPOracle5.17.07.1Oracle Peoplesoft Enterprise Peopletools
APPOracle8.568.578.58Oracle Storagetek Tape Analytics Sw Tool
APPOracle2.3Oracle Tape Library Acsls
APPOracle8.5Oracle Tape Virtual Storage Manager Gui
APPOracle6.2Oracle Vm Virtualbox
APPOracle5.2.366.1.0 – 6.1.2 (excl.)< 5.2.366.0.0 – 6.0.16 (excl.)Oracle Weblogic Server
APPOracle10.3.6.0.012.1.3.0.0
CISA KEV — detailsi
- Vendori
- Oracle ↗
- Producti
- WebLogic Server
- Added to KEVi
- January 10, 2022
- Remediation deadline (US Federal)i
- July 10, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Related vulnerabilities
Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
Oracle WebLogic Server — Auth Bypass w komponencie Console (RCE)
RCE bez uwierzytelnienia w konsoli Oracle WebLogic Server
RCE w Oracle WebLogic Server — przejęcie serwera przez IIOP/T3