cbcvebase.
CVE-2025-21535
published 2025-01-21

CVE-2025-21535: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.80%
52.6th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

4 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracle_corporationoracle_weblogic_server
oracle_corporationoracle_weblogic_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-21535 exploits Oracle WebLogic Server via the T3 and IIOP protocols — monitor and restrict inbound T3 (default port 7001/7002) and IIOP traffic to WebLogic servers from untrusted networks
  • Affected versions are WebLogic 12.2.1.4.0 and 14.1.1.0.0 — prioritize detection and patching on hosts running these specific versions
  • Successful exploitation results in full server takeover (RCE) — alert on unexpected process spawning from WebLogic JVM processes (e.g., java.exe or weblogic spawning cmd.exe, sh, curl, wget)
  • ·Exploitation requires network access via T3 or IIOP protocols; blocking or filtering these protocols at the network perimeter for untrusted sources significantly reduces attack surface
  • ·The vulnerability is in the Core component of Oracle WebLogic Server — patching guidance is provided in Oracle's January 2025 Critical Patch Update (cpujan2025)

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.