Unauthenticated Remote Takeover of Oracle WebLogic Server (CVSS 9.8)
A vulnerability is present in Oracle WebLogic Server, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.1.0.0. This flaw can be easily exploited by unauthenticated attackers with network access via T3 and IIOP. If the attack is successful, the attacker can take over the Oracle WebLogic Server. The issue has a CVSS 3.1 Base Score of 9.8, impacting Confidentiality, Integrity, and Availability. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
oracle weblogic server 12.2.1.4.0 |
||
oracle weblogic server 14.1.1.0.0 |