target entity

WebLogic Server

12 source-linked records in the current knowledge graph.

high

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-21182EPSS 49.7%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-2883EPSS 94.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-14644EPSS 94.5%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3506: Oracle WebLogic Server OS Command Injection Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-3506EPSS 96.3%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21839: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. Required action: Apply updates per vendor instructions.

CVE-2023-21839EPSS 99.8%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2018-2628: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. Required action: Apply updates per vendor instructions.

CVE-2018-2628EPSS 99.4%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2725: Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Required action: Apply updates per vendor instructions.

CVE-2019-2725EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14750: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Required action: Apply updates per vendor instructions.

CVE-2020-14750CVE-2020-14882EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Required action: Apply updates per vendor instructions.

CVE-2020-14883EPSS 97.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution