NA
CVSSv4

CVE-2024-21216

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00509 | KEV: Not Included
Published: 15/10/2024 Updated: 18/10/2024

Vulnerability Summary

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle weblogic server 12.2.1.4.0

oracle weblogic server 14.1.1.0.0

Github Repositories

Hi there 👋 CVE-2024-21182 : Oracle Critical Patch Update Advisory - July 2024 CVE-2024-21216 : Oracle Critical Patch Update Advisory - October 2024 CVE-2024-42323 : Apache HertzBeat: RCE by snakeYaml deser load malicious xml CVE-2024-45505 : Apache HertzBeat (incubating): Exists Native Deser RCE and file writing vulnerabilities