Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 1 of 16
CVE-2019-2725P1CRITICALCVSS 9.8KEVPoCRansomwarev10.3.6.0.0v12.1.3.0.02019-04-26
CVE-2019-2725 [CRITICAL] CWE-74 CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2018-2628P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2018-04-19
CVE-2018-2628 [CRITICAL] CWE-502 CVE-2018-2628: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-14882P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14882 [CRITICAL] CVE-2020-14882: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-14750P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-11-02
CVE-2020-14750 [CRITICAL] CVE-2020-14750: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-2883P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2883 [CRITICAL] CVE-2020-2883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2022-22965P1CRITICALCVSS 9.8KEVPoCRansomwarev12.2.1.3.0v12.2.1.4.0+1 more2022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2015-4852P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.2.0.0+2 more2015-11-18
CVE-2015-4852 [CRITICAL] CWE-502 CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allo
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the
nvd
CVE-2020-14644P1CRITICALCVSS 9.8KEVPoCv12.2.1.3.0v12.2.1.4.0+1 more2020-07-15
CVE-2020-14644 [CRITICAL] CVE-2020-14644: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability c
nvd
CVE-2017-5638P1CRITICALCVSS 9.8KEVPoCRansomwarev10.3.6.0.0v12.1.3.0.0+2 more2017-03-11
CVE-2017-5638 [CRITICAL] CWE-755 CVE-2017-5638: The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has in
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild i
nvd
CVE-2020-2551P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2551 [CRITICAL] CVE-2020-2551: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2017-10271P1HIGHCVSS 7.5KEVPoCRansomwarev10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10271 [HIGH] CWE-306 CVE-2017-10271: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2023-21839P1HIGHCVSS 7.5KEVPoCv12.2.1.3.0v12.2.1.4.0+1 more2023-01-18
CVE-2023-21839 [HIGH] CWE-502 CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2017-3506P1HIGHCVSS 7.4KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2017-04-24
CVE-2017-3506 [HIGH] CWE-78 CVE-2017-3506: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attac
nvd
CVE-2020-14883P1HIGHCVSS 7.2KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14883 [HIGH] CVE-2020-14883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of t
nvd
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCv12.1.3.0.0v12.2.1.3.0+2 more2020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2024-21182P1HIGHCVSS 7.5KEVPoCv12.2.1.4.0v14.1.1.0.02024-07-16
CVE-2024-21182 [HIGH] CVE-2024-21182: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2729P1CRITICALCVSS 9.8ExploitedPoCRansomwarev10.3.6.0.0v12.1.3.0.0+1 more2019-06-19
CVE-2019-2729 [CRITICAL] CWE-284 CVE-2019-2729: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2018-2893P1CRITICALCVSS 9.8ExploitedPoCv10.3.6.0.0v12.1.3.0.0+2 more2018-07-18
CVE-2018-2893 [CRITICAL] CVE-2018-2893: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2022-21371P1HIGHCVSS 7.5ExploitedPoCv12.1.3.0.0v12.2.1.3.0+2 more2022-01-19
CVE-2022-21371 [HIGH] CWE-22 CVE-2022-21371: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Cont
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2018-2894P1CRITICALCVSS 9.8ExploitedPoCRansomwarev10.3.6.0.0v12.1.3.0.0+2 more2018-07-18
CVE-2018-2894 [CRITICAL] CVE-2018-2894: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerab
nvd
1 / 16Next →