Oracle Vulnerabilities and Affected Products
Vulnerabilities associated with WebLogic Server.
Products
Clear product- Advanced Outbound Telephony38 vulnerabilities
- Marketing23 vulnerabilities
- Java SE21 vulnerabilities
- WebLogic Server21 vulnerabilities
- One-to-One Fulfillment19 vulnerabilities
- weblogic_server19 vulnerabilities
- MySQL Server17 vulnerabilities
- communications_diameter_signaling_router13 vulnerabilities
- enterprise_manager_base_platform13 vulnerabilities
- FLEXCUBE Universal Banking13 vulnerabilities
- agile_plm12 vulnerabilities
- autovue_for_agile_product_lifecycle_management12 vulnerabilities
- banking_digital_experience12 vulnerabilities
- communications_calendar_server12 vulnerabilities
- communications_element_manager12 vulnerabilities
- communications_evolved_communications_application_server12 vulnerabilities
- communications_instant_messaging_server12 vulnerabilities
- communications_network_charging_and_control12 vulnerabilities
- communications_session_route_manager12 vulnerabilities
- financial_services_analytical_applications_infrastructure12 vulnerabilities
- financial_services_institutional_performance_analytics12 vulnerabilities
- financial_services_price_creation_and_discovery12 vulnerabilities
- financial_services_retail_customer_analytics12 vulnerabilities
- global_lifecycle_management_opatch12 vulnerabilities
- insurance_policy_administration_j2ee12 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-21535CRITICAL | Oracle WebLogic Server Missing Authentication for Critical FunctionVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/… CWE-306Jan 21, 2025 | CVSS9.8v3.1 | EPSS0.807% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2024-21182HIGH | Oracle WebLogic Server Unspecified VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidenti… Jul 16, 2024 | CVSS7.5v3.1 | EPSS50% | PoCs4 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22069CRITICAL | Oracle WebLogic Server Core Component T3/IIOP Unauthenticated VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/… CWE-306Oct 17, 2023 | CVSS9.8v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2023-21839HIGH | Oracle WebLogic Server Unspecified VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5… | CVSS7.5v3.1 | EPSS99.8% | PoCs10 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-21371HIGH | Oracle WebLogic Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 B… | CVSS7.5v3.1 | EPSS92.6% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-2135CRITICAL | Oracle Fusion Middleware WebLogic Server Coherence Container Security BypassVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). … Apr 22, 20211 related artifact | CVSS9.8v3.1 | EPSS8.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-14750CRITICAL | Oracle WebLogic Server Remote Code Execution VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im… Nov 1, 20201 related artifact | CVSS9.8v3.1 | EPSS99.3% | PoCs5 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-14882CRITICAL | Oracle WebLogic Server Remote Code Execution VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im… Oct 21, 20201 related artifact | CVSS9.8v3.1 | EPSS>99.9% | PoCs36 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-14883HIGH | Oracle WebLogic Server Unspecified VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability im… Oct 21, 20201 related artifact | CVSS7.2v3.1 | EPSS97.9% | PoCs9 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-14644CRITICAL | Oracle WebLogic Server Remote Code Execution VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C… Jul 15, 20201 related artifact | CVSS9.8v3.1 | EPSS94.5% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-2883CRITICAL | Oracle WebLogic Server Unspecified VulnerabilityVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVS… Apr 15, 20201 related artifact | CVSS9.8v3.1 | EPSS94.9% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-2725CRITICAL | Oracle WebLogic Server, InjectionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS… | CVSS9.8v3.1 | EPSS>99.9% | PoCs25 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2019-2618MEDIUM | Oracle WebLogic Server WLS Core Components VulnerabilityVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as u… Apr 23, 2019 | CVSS5.5v3.0 | EPSS33.4% | PoCs7 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-2893CRITICAL | Oracle WebLogic Server Core Components T3 Network Access VulnerabilityVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts… Jul 18, 20181 related artifact | CVSS9.8v3.0 | EPSS71.2% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-2894CRITICAL | Oracle Fusion Middleware WebLogic Server Unauthenticated Security BypassVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS V… Jul 18, 20181 related artifact | CVSS9.8v3.0 | EPSS50.2% | PoCs5 | SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2018-2628CRITICAL | Oracle WebLogic Server Unspecified VulnerabilityVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts… | CVSS9.8v3.1 | EPSS99.4% | PoCs20 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-10271HIGH | Oracle Corporation WebLogic Server Remote Code Execution VulnerabilityVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N… | CVSS7.5v3.1 | EPSS>99.9% | PoCs35 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2017-3506HIGH | Oracle WebLogic Server OS Command Injection VulnerabilityVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server acc… | CVSS7.4v3.1 | EPSS96.3% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-3248CRITICAL | Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code ExecutionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). Jan 27, 2017 | CVSS9.8v3.0 | EPSS97.3% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-0638CRITICAL | Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java DeserializationUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service. Apr 21, 2016 | CVSS9.8v3.0 | EPSS62.9% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2015-4852CRITICAL | Oracle WebLogic Server Deserialization of Untrusted Data VulnerabilityThe WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product. | CVSS9.8v3.1 | EPSS96% | PoCs8 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |