Unauthenticated Remote Access Vulnerability in Oracle WebLogic Server
CVE-2023-21979

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access over T3 to exploit weaknesses in the Core component. Attackers can gain unauthorized access, potentially compromising sensitive data and resources on the server. Affected versions include 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. Organizations using these versions are urged to apply security patches promptly to protect their data integrity and secure their systems against unauthorized access.

Affected Version(s)

WebLogic Server 12.2.1.3.0

WebLogic Server 12.2.1.4.0

WebLogic Server 14.1.1.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.