Unauthenticated Data Compromise in Oracle WebLogic Server
Oracle WebLogic Server in Oracle Fusion Middleware has a vulnerability. This affects versions 12.2.1.4.0 and 14.1.1.0.0. Attackers can exploit this easily if they have network access via T3 or IIOP. They do not need to be authenticated. If successful, they can get unauthorized access to sensitive data or all data on Oracle WebLogic Server. The vulnerability has a CVSS 3.1 Base Score of 7.5, mainly affecting confidentiality (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
oracle weblogic server 12.2.1.4.0 |
||
oracle weblogic server 14.1.1.0.0 |