Oracle WebLogic Server Vulnerability: Unauthenticated Hang or Crash Possible via HTTP
CVE-2024-21274

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

An unauthenticated network vulnerability in Oracle WebLogic Server's Console component allows attackers with HTTP access to exploit the system. Successful exploitation can lead to unauthorized actions resulting in the hang or frequent crashing of the server, creating a complete denial of service condition. Affected versions include Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0, which are critical in many enterprise environments.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.