Unauthenticated Access Vulnerability in Oracle WebLogic Server
CVE-2024-20931
Key Information:
- Vendor
- Oracle
- Status
- Vendor
- CVE Published:
- 17 February 2024
Badges
Summary
A significant vulnerability exists in Oracle WebLogic Server, part of the Oracle Fusion Middleware suite, specifically in its core component. Versions 12.2.1.4.0 and 14.1.1.0.0 are susceptible. Exploitation of this vulnerability enables an unauthenticated attacker with network access through T3 and IIOP protocols to compromise the server. Such unauthorized access can lead to the exposure of critical data, potentially granting attackers complete control over all accessible information within the Oracle WebLogic Server environment.
Affected Version(s)
WebLogic Server 12.2.1.4.0
WebLogic Server 14.1.1.0.0
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
Oracle Weblogic Server Flaw Allows Attackers Full Control - PoC Released
A new secondary JNDI injection vulnerability was discovered in a recent version of WebLogic, allowing attackers to trigger JNDI injection

π Exploit for CVE-2024-20931
Exploit for CVE-2024-20931 | Sploitus | Exploit & Hacktool Search Engine
References
EPSS Score
87% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
Vulnerability published
- π°
First article discovered by Sploitus
Vulnerability Reserved