Showing 21 vulnerabilities on this page for WebLogic Server

Signals CISA KEV Ransomware Nuclei
Oracle vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Oracle WebLogic Server Missing Authentication for Critical Function

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/

CWE-306Jan 21, 2025
CVSS9.8v3.1EPSS0.807%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Oracle WebLogic Server Unspecified Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidenti

Jul 16, 2024
CVSS7.5v3.1EPSS50%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Oracle WebLogic Server Core Component T3/IIOP Unauthenticated Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/

CWE-306Oct 17, 2023
CVSS9.8v3.1EPSS0.75%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Oracle WebLogic Server Unspecified Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5

CWE-306CWE-502Jan 17, 20231 related artifact
CVSS7.5v3.1EPSS99.8%PoCs10SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 B

CWE-22Jan 19, 20221 related artifact
CVSS7.5v3.1EPSS92.6%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle Fusion Middleware WebLogic Server Coherence Container Security Bypass

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).

Apr 22, 20211 related artifact
CVSS9.8v3.1EPSS8.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Remote Code Execution Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im

Nov 1, 20201 related artifact
CVSS9.8v3.1EPSS99.3%PoCs5SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Remote Code Execution Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im

Oct 21, 20201 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs36SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Unspecified Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability im

Oct 21, 20201 related artifact
CVSS7.2v3.1EPSS97.9%PoCs9SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Remote Code Execution Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C

Jul 15, 20201 related artifact
CVSS9.8v3.1EPSS94.5%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Unspecified Vulnerability

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVS

Apr 15, 20201 related artifact
CVSS9.8v3.1EPSS94.9%PoCs7SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server, Injection

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS

CWE-74Apr 26, 20191 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs25SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server WLS Core Components Vulnerability

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as u

Apr 23, 2019
CVSS5.5v3.0EPSS33.4%PoCs7SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Oracle WebLogic Server Core Components T3 Network Access Vulnerability

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts

Jul 18, 20181 related artifact
CVSS9.8v3.0EPSS71.2%PoCs6SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle Fusion Middleware WebLogic Server Unauthenticated Security Bypass

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS V

Jul 18, 20181 related artifact
CVSS9.8v3.0EPSS50.2%PoCs5SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server Unspecified Vulnerability

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts

CWE-502Apr 19, 20181 related artifact
CVSS9.8v3.1EPSS99.4%PoCs20SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N

CWE-306Oct 19, 20171 related artifact
CVSS7.5v3.1EPSS>99.9%PoCs35SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle WebLogic Server OS Command Injection Vulnerability

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server acc

CWE-78Apr 24, 20171 related artifact
CVSS7.4v3.1EPSS96.3%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).

Jan 27, 2017
CVSS9.8v3.0EPSS97.3%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.

Apr 21, 2016
CVSS9.8v3.0EPSS62.9%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CWE-502CWE-77Nov 18, 2015
CVSS9.8v3.1EPSS96%PoCs8SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX