CVE-2016-0638Oracle Weblogic Server vulnerability

15 documents5 sources
Severity
9.8CRITICALNVD
EPSS
70.9%
top 1.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 14

Description

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDoracle/weblogic_server4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hhg5-g8w6-h56h: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 102022-05-14
CVEList
CVE-2016-0638: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 102016-04-21

🕵️Threat Intelligence

3
Tenable
Hunting for Web Shells2016-12-20
Tenable
Hunting for Web Shells2016-12-20
Tenable
[R1] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization Remote Code Execution2016-04-19

💬Community

9
Bugzilla
CVE-2016-1658 chromium-browser: potential leak of sensitive information to malicious extensions2016-04-14
Bugzilla
CVE-2016-1654 chromium-browser: uninitialized memory read in media2016-04-14
Bugzilla
CVE-2016-1653 chromium-browser: out-of-bounds write in V82016-04-14
Bugzilla
CVE-2016-1659 chromium-browser: various fixes from internal audits2016-04-14
Bugzilla
CVE-2016-1652 chromium-browser: universal XSS in extension bindings2016-04-14
CVE-2016-0638 — Oracle Weblogic Server vulnerability | cvebase