Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 11 of 16
CVE-2021-2211P3MEDIUMCVSS 5.9v10.3.6.0.0v12.2.1.3.0+2 more2021-04-22
CVE-2021-2211 [MEDIUM] CVE-2021-2211: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of th
nvd
CVE-2022-23437P3MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.0+1 more2022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2018-1313P3MEDIUMCVSS 5.3v12.2.1.32018-05-07
CVE-2018-1313 [MEDIUM] CVE-2018-1313: In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy fi
nvd
CVE-2021-2294P3MEDIUMCVSS 6.5v10.3.6.0.0v12.1.3.0.0+3 more2021-04-22
CVE-2021-2294 [MEDIUM] CVE-2021-2294: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2022-21353P3MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.0+1 more2022-01-19
CVE-2022-21353 [MEDIUM] CVE-2022-21353: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul
nvd
CVE-2022-21347P3MEDIUMCVSS 6.5v12.1.3.0.0v12.2.1.3.0+2 more2022-01-19
CVE-2022-21347 [MEDIUM] CVE-2022-21347: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerabili
nvd
CVE-2019-2418P3MEDIUMCVSS 6.5v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2418 [MEDIUM] CVE-2019-2418: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Oracle
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.0+1 more2021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2018-1257P3MEDIUMCVSS 6.5v10.3.6.0.0v12.1.3.0.0+1 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2018-3248P3MEDIUMCVSS 6.5v10.3.6.0.02018-10-17
CVE-2018-3248 [MEDIUM] CVE-2018-3248: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected is 10.3.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person
nvd
CVE-2019-2888P3MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+1 more2019-10-16
CVE-2019-2888 [MEDIUM] CVE-2019-2888: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Cont
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2017-10148P3MEDIUMCVSS 5.8v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10148 [MEDIUM] CVE-2017-10148: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in
nvd
CVE-2022-21548P3MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.0+1 more2022-07-19
CVE-2022-21548 [MEDIUM] CVE-2022-21548: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can
nvd
CVE-2025-30753P3MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.0+1 more2025-07-15
CVE-2025-30753 [MEDIUM] CWE-400 CVE-2025-30753: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability ca
nvd
CVE-2021-29425P4MEDIUMCVSS 4.8v12.1.3.0.0v12.2.1.3.0+2 more2021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v12.2.1.3.02018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2019-2452P4MEDIUMCVSS 6.7v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2452 [MEDIUM] CVE-2019-2452: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2023-22040P4MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.02023-07-18
CVE-2023-22040 [MEDIUM] CVE-2023-22040: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can res
nvd
CVE-2019-3740P4MEDIUMCVSS 6.5v10.3.6.0.0v12.1.3.0.0+3 more2019-09-18
CVE-2019-3740 [MEDIUM] CWE-310 CVE-2019-3740: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
nvd
CVE-2016-3416P4MEDIUMCVSS 6.1v10.3.6.0.0v12.1.2.0.0+2 more2016-04-21
CVE-2016-3416 [MEDIUM] CVE-2016-3416: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality and integrity via vectors related to Console.
nvd