Denial of Service Vulnerability in Oracle WebLogic Server from Oracle Fusion Middleware
CVE-2023-22031

4.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2023

Summary

A security vulnerability has been identified in the Oracle WebLogic Server component of Oracle Fusion Middleware. This flaw affects specific supported versions, including 14.1.1.0.0 and 12.2.1.4.0, allowing high-privileged attackers with network access via T3 and IIOP protocols to compromise the server. Successful exploitation of this flaw can lead to unauthorized actions such as causing the server to hang or repeatedly crash, resulting in denial of service for legitimate users.

Affected Version(s)

WebLogic Server 14.1.1.0.0

WebLogic Server 12.2.1.4.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.