Denial of Service Vulnerability in Oracle WebLogic Server by Oracle
CVE-2023-21964

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in Oracle WebLogic Server within Oracle Fusion Middleware, affecting specific versions that allow unauthenticated network attackers to exploit the T3 protocol. This vulnerability can be easily exploited, potentially leading to significant disruptions by causing the server to hang or repeatedly crash, impacting service availability. Organizations using the affected versions should prioritize applying the necessary patches to mitigate the risk.

Affected Version(s)

WebLogic Server 12.2.1.3.0

WebLogic Server 12.2.1.4.0

WebLogic Server 14.1.1.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.