Denial of Service Vulnerability in Oracle WebLogic Server by Oracle
CVE-2025-30753

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-30753?

A security vulnerability exists in Oracle WebLogic Server affecting certain versions of Oracle Fusion Middleware. Attackers with low privileges can exploit this vulnerability via HTTP to cause significant disruptions, such as inducing repeated crashes or hangs of the server, thereby leading to a Denial of Service. This issue highlights the importance of securing Oracle WebLogic Server to ensure seamless operations and prevent unauthorized access.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

Oracle WebLogic Server 14.1.2.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.