CVE-2024-21182
published 2024-07-16CVE-2024-21182: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and…
PriorityP188high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-04
Exploited in the wild
EPSS
49.69%
98.8th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor and restrict inbound T3 and IIOP protocol traffic to Oracle WebLogic Server instances, as these are the attack vectors for CVE-2024-21182 exploitation. ↗
- →Identify exposed Oracle WebLogic Server instances running versions 12.2.1.4.0 and 14.1.1.0.0, which are the confirmed affected versions actively targeted in the wild. ↗
- →Prior WebLogic flaws have been exploited to enlist servers into botnets, mine cryptocurrency, and deploy ransomware — hunt for these post-exploitation behaviors on WebLogic hosts. ↗
- ·No public proof-of-concept or technical exploitation details have been disclosed; the vulnerability mechanism remains unspecified by Oracle. ↗
- ·The vulnerability is confirmed exploitable only on Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0; other versions are not listed as affected. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rr6f-mqf5-f7wc: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
ghsa_unreviewed·2024-07-17
CVE-2024-21182 [HIGH] GHSA-rr6f-mqf5-f7wc: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability
vulncheck·2024·CVSS 7.5
CVE-2024-21182 [HIGH] Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Affected: Oracle WebLogic Server
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/a0055cc0670c; https://vulncheck.com/xdb/fa0ee208a4c9
CISA
Oracle WebLogic Server Unspecified Vulnerability
cisa·2026-06-01·CVSS 7.5
CVE-2024-21182 [HIGH] Oracle WebLogic Server Unspecified Vulnerability
Vulnerability: Oracle WebLogic Server Unspecified Vulnerability
Affected: Oracle WebLogic Server
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182
Remediation Due Date: 2026-06-04
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2024-21182
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-21182 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2024-21182
Oracle Oracle Fusion Middleware Risk Matrix: Core vulnerability
CVE: CVE-2024-21182
CVSS: 7.5
Protocol: T3, IIOP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA flags two-year-old Oracle flaw as actively exploited in attacks
blogs_bleepingcomputer·2026-06-02·CVSS 7.5
CVE-2024-21182 [HIGH] CISA flags two-year-old Oracle flaw as actively exploited in attacks
## CISA flags two-year-old Oracle flaw as actively exploited in attacks
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.
Oracle WebLogic Server is an enterprise-grade Java app server used as middleware for large, multi-tier distributed applications.
Tracked as CVE-2024-21182 , this security flaw can be exploited remotely by threat actors with no privileges in low-complexity attacks targeting systems running Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
"Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to
Hackernews
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
blogs_hackernews·2026-06-02·CVSS 7.5
CVE-2024-21182 [HIGH] Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities ( KEV ) Catalog, based on evidence of active exploitation.
The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was patched by Oracle in July 2024.
"Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via
2024-07-16
Published
2026-06-01
Added to CISA KEV
Exploited in the wild