7.5
CVSSv3

CVE-2023-22086

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00293 | KEV: Not Included
Published: 17/10/2023 Updated: 21/11/2024

Vulnerability Summary

Unauthenticated Data Compromise in Oracle WebLogic Server

Oracle WebLogic Server in Oracle Fusion Middleware has a vulnerability. This affects versions 12.2.1.4.0 and 14.1.1.0.0. Attackers can exploit this easily if they have network access via T3 or IIOP. They do not need to be authenticated. If successful, they can get unauthorized access to sensitive data or all data on Oracle WebLogic Server. The vulnerability has a CVSS 3.1 Base Score of 7.5, mainly affecting confidentiality (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle weblogic server 12.2.1.4.0

oracle weblogic server 14.1.1.0.0