Oracle Weblogic Server vulnerabilities
306 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
306
CISA KEV
15
actively exploited
Public exploits
33
Exploited in wild
22
Severity breakdown
CRITICAL81HIGH92MEDIUM129LOW4
Vulnerabilities
Page 12 of 16
CVE-2019-2618MEDIUMCVSS 5.5v10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2618 [MEDIUM] CVE-2019-2618: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2019-2452MEDIUMCVSS 6.7v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2452 [MEDIUM] CVE-2019-2452: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2019-2395MEDIUMCVSS 5.4v10.3.6.02019-01-16
CVE-2019-2395 [MEDIUM] CVE-2019-2395: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected is 10.3.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2441MEDIUMCVSS 5.3v12.2.1.32019-01-16
CVE-2019-2441 [MEDIUM] CVE-2019-2441: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: App
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can re
nvd
CVE-2019-2418MEDIUMCVSS 6.5v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2418 [MEDIUM] CVE-2019-2418: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Oracle
nvd
CVE-2019-2398MEDIUMCVSS 4.3v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2398 [MEDIUM] CVE-2019-2398: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Deployment). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2018-15756HIGHCVSS 7.5v10.3.6.0.0v12.1.3.0.0+2 more2018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2018-3197CRITICALCVSS 9.8v12.1.3.0.02018-10-17
CVE-2018-3197 [CRITICAL] CVE-2018-3197: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in tak
nvd
CVE-2018-3191CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2018-10-17
CVE-2018-3191 [CRITICAL] CVE-2018-3191: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2018-3252CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2018-10-17
CVE-2018-3252 [CRITICAL] CVE-2018-3252: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2018-3201CRITICALCVSS 9.8v12.2.1.3.02018-10-17
CVE-2018-3201 [CRITICAL] CVE-2018-3201: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in tak
nvd
CVE-2018-3245CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+1 more2018-10-17
CVE-2018-3245 [CRITICAL] CWE-502 CVE-2018-3245: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this v
nvd
CVE-2018-3246HIGHCVSS 7.5v12.1.3.0.0v12.2.1.3+1 more2018-10-17
CVE-2018-3246 [HIGH] CVE-2018-3246: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resu
nvd
CVE-2018-3213HIGHCVSS 7.5fixed in 12.2.1.3.02018-10-17
CVE-2018-3213 [HIGH] CVE-2018-3213: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Doc
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Docker Images). The supported version that is affected is prior to Docker 12.2.1.3.20180913. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability ca
nvd
CVE-2018-2902MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.02018-10-17
CVE-2018-2902 [MEDIUM] CVE-2018-2902: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Con
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Console). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2018-3248MEDIUMCVSS 6.5v10.3.6.0.02018-10-17
CVE-2018-3248 [MEDIUM] CVE-2018-3248: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected is 10.3.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person
nvd
CVE-2018-3249MEDIUMCVSS 6.5v10.3.6.0.02018-10-17
CVE-2018-3249 [MEDIUM] CVE-2018-3249: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected is 10.3.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2018-3250MEDIUMCVSS 6.1v10.3.6.0.02018-10-17
CVE-2018-3250 [MEDIUM] CVE-2018-3250: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected is 10.3.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person
nvd
CVE-2018-11771MEDIUMCVSS 5.5v14.1.1.0.02018-08-16
CVE-2018-11771 [MEDIUM] CWE-835 CVE-2018-11771: When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service att
nvd