cbcvebase.
CVE-2024-21182
published 2024-07-16

CVE-2024-21182: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and…

PriorityP188high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-04
Exploited in the wild
EPSS
49.69%
98.8th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected

4 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

portT3
portIIOP
  • Monitor and restrict inbound T3 and IIOP protocol traffic to Oracle WebLogic Server instances, as these are the attack vectors for CVE-2024-21182 exploitation.
  • Identify exposed Oracle WebLogic Server instances running versions 12.2.1.4.0 and 14.1.1.0.0, which are the confirmed affected versions actively targeted in the wild.
  • Prior WebLogic flaws have been exploited to enlist servers into botnets, mine cryptocurrency, and deploy ransomware — hunt for these post-exploitation behaviors on WebLogic hosts.
  • ·No public proof-of-concept or technical exploitation details have been disclosed; the vulnerability mechanism remains unspecified by Oracle.
  • ·The vulnerability is confirmed exploitable only on Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0; other versions are not listed as affected.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.