Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 12 of 16
CVE-2020-2766P4MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2766 [MEDIUM] CVE-2020-2766: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerab
nvd
CVE-2017-10336P4MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10336 [MEDIUM] CVE-2017-10336: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2019-3739P4MEDIUMCVSS 6.5v10.3.6.0.0v12.2.1.3.0+2 more2019-09-18
CVE-2019-3739 [MEDIUM] CWE-310 CVE-2019-3739: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Dis
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
nvd
CVE-2019-2615P4MEDIUMCVSS 4.9v10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2615 [MEDIUM] CVE-2019-2615: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2018-11039P4MEDIUMCVSS 5.9v10.3.6.0.0v12.1.3.0.0+1 more2018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2008-2579P4HIGHCVSS 7.5v6.1v7.0+5 more2008-07-15
CVE-2008-2579 [HIGH] CVE-2008-2579: Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers compone
Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
nvd
CVE-2021-2403P4MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2403 [MEDIUM] CVE-2021-2403: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2018-2625P4MEDIUMCVSS 5.3v12.1.3.0.0v12.2.1.2.0+1 more2018-01-18
CVE-2018-2625 [MEDIUM] CVE-2018-2625: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerabil
nvd
CVE-2023-21960P4MEDIUMCVSS 5.6v12.2.1.3.0v12.2.1.4.02023-04-18
CVE-2023-21960 [MEDIUM] CVE-2023-21960: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2025-61764P4MEDIUMCVSS 5.3v12.2.1.4.0v14.1.1.0.0+1 more2025-10-21
CVE-2025-61764 [MEDIUM] CWE-200 CVE-2025-61764: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability c
nvd
CVE-2016-0700P4MEDIUMCVSS 6.1v10.3.6.0.0v12.1.2.0.0+1 more2016-04-21
CVE-2016-0700 [MEDIUM] CVE-2016-0700: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675.
nvd
CVE-2016-0675P4MEDIUMCVSS 6.1v10.3.6.0.0v12.1.2.0.0+1 more2016-04-21
CVE-2016-0675 [MEDIUM] CVE-2016-0675: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700.
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3v12.2.1.3.0v12.2.1.4.02020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2025-50073P4MEDIUMCVSS 6.1v12.2.1.4.0v14.1.1.0.0+1 more2025-07-15
CVE-2025-50073 [MEDIUM] CWE-285 CVE-2025-50073: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Cont
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require huma
nvd
CVE-2024-20986P4MEDIUMCVSS 6.1v12.2.1.4.0v14.1.1.0.02024-02-17
CVE-2024-20986 [MEDIUM] CWE-352 CVE-2024-20986: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a pe
nvd
CVE-2019-2824P4MEDIUMCVSS 5.5v10.3.6.0.0v12.1.3.0.0+1 more2019-07-23
CVE-2019-2824 [MEDIUM] CVE-2019-2824: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2019-2827P4MEDIUMCVSS 5.5v10.3.6.0.0v12.1.3.0.0+1 more2019-07-23
CVE-2019-2827 [MEDIUM] CVE-2019-2827: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2019-2441P4MEDIUMCVSS 5.3v12.2.1.32019-01-16
CVE-2019-2441 [MEDIUM] CVE-2019-2441: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: App
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can re
nvd
CVE-2021-2204P4MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+3 more2021-04-22
CVE-2021-2204 [MEDIUM] CVE-2021-2204: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2018-2998P4MEDIUMCVSS 5.4v10.3.6.0.0v12.1.3.0.0+2 more2018-07-18
CVE-2018-2998 [MEDIUM] CVE-2018-2998: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: SAM
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: SAML). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability c
nvd