Vulnerability in Oracle WebLogic Server Affecting Fusion Middleware
CVE-2024-20927

8.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 February 2024

Summary

A vulnerability exists in Oracle WebLogic Server that could allow unauthenticated attackers with network access via HTTP to exploit the server. This vulnerability affects supported versions, including 12.2.1.4.0 and 14.1.1.0.0, potentially allowing attackers to create, delete, or modify critical data accessible through Oracle WebLogic Server. While primarily involving Oracle WebLogic Server, successful exploits may also have implications for additional products, causing a significant scope change. Organizations using impacted versions should prioritize assessing and mitigating risk to safeguard their data and systems.

Affected Version(s)

WebLogic Server 12.2.1.4.0

WebLogic Server 14.1.1.0.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.