CVE-2007-2699

BEA WebLogic Express/WebLogic Server 9.0-9.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2699. PoCs published by Steven Seeley, sinn3r, including Metasploit module exploits/windows/http/oats_weblogic_console.

AI-analyzed exploit summary This Metasploit module exploits a feature in Oracle WebLogic Server's Administration Console to deploy a malicious WAR file, achieving remote code execution. It leverages default credentials ('oats') for authentication and targets versions 12 or prior.

Description

The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Steven Seeley, sinn3r · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/oats_weblogic_console.rb

This Metasploit module exploits a feature in Oracle WebLogic Server's Administration Console to deploy a malicious WAR file, achieving remote code execution. It leverages default credentials ('oats') for authentication and targets versions 12 or prior.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server Administration Console 12 or prior
Auth required
Prerequisites: Network access to WebLogic Administration Console · Valid credentials (default 'oats' account)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018057
Patch, Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/231
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36069
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34289
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25284
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1815

Scores

EPSS 0.3088
EPSS Percentile 98.0%

Details

Status published
Products (2)
bea/weblogic_server 9.0 (2 CPE variants)
bea/weblogic_server 9.1 (2 CPE variants)
Published May 16, 2007
Tracked Since Feb 18, 2026