Vulnerability in Oracle WebLogic Server Affecting Fusion Middleware
CVE-2024-20927
8.6HIGH
Summary
A vulnerability exists in Oracle WebLogic Server that could allow unauthenticated attackers with network access via HTTP to exploit the server. This vulnerability affects supported versions, including 12.2.1.4.0 and 14.1.1.0.0, potentially allowing attackers to create, delete, or modify critical data accessible through Oracle WebLogic Server. While primarily involving Oracle WebLogic Server, successful exploits may also have implications for additional products, causing a significant scope change. Organizations using impacted versions should prioritize assessing and mitigating risk to safeguard their data and systems.
Affected Version(s)
WebLogic Server 12.2.1.4.0
WebLogic Server 14.1.1.0.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database