Unauthenticated Access Vulnerability in Oracle WebLogic Server
CVE-2024-20931

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 February 2024

Badges

πŸ“° News Worthy

Summary

A significant vulnerability exists in Oracle WebLogic Server, part of the Oracle Fusion Middleware suite, specifically in its core component. Versions 12.2.1.4.0 and 14.1.1.0.0 are susceptible. Exploitation of this vulnerability enables an unauthenticated attacker with network access through T3 and IIOP protocols to compromise the server. Such unauthorized access can lead to the exposure of critical data, potentially granting attackers complete control over all accessible information within the Oracle WebLogic Server environment.

Affected Version(s)

WebLogic Server 12.2.1.4.0

WebLogic Server 14.1.1.0.0

News Articles

πŸ’€ Exploit for CVE-2024-20931

Exploit for CVE-2024-20931 | Sploitus | Exploit & Hacktool Search Engine

11 months ago

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • πŸ“°

    First article discovered by Sploitus

  • Vulnerability Reserved

.