Oracle Weblogic Server vulnerabilities

306 known vulnerabilities affecting oracle/weblogic_server.

Total CVEs
306
CISA KEV
15
actively exploited
Public exploits
33
Exploited in wild
22
Severity breakdown
CRITICAL81HIGH92MEDIUM129LOW4

Vulnerabilities

Page 14 of 16
CVE-2017-10352CRITICALCVSS 9.9v10.3.6.0.0v12.1.3.0.0+3 more2017-10-19
CVE-2017-10352 [CRITICAL] CVE-2017-10352: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. W
nvd
CVE-2017-10271HIGHCVSS 7.5KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10271 [HIGH] CWE-306 CVE-2017-10271: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2017-10152MEDIUMCVSS 6.5v10.3.6.0.0v12.1.3.0.02017-10-19
CVE-2017-10152 [MEDIUM] CWE-200 CVE-2017-10152: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerabilit
nvd
CVE-2017-10336MEDIUMCVSS 5.3v10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10336 [MEDIUM] CVE-2017-10336: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2017-10334MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10334 [MEDIUM] CWE-200 CVE-2017-10334: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful atta
nvd
CVE-2017-10137CRITICALCVSS 10.0v10.3.6.0.0v12.1.3.0.02017-08-08
CVE-2017-10137 [CRITICAL] CVE-2017-10137: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JND Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, att
nvd
CVE-2017-10147HIGHCVSS 8.6v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10147 [HIGH] CVE-2017-10147: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Or
nvd
CVE-2017-10178MEDIUMCVSS 6.1v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10178 [MEDIUM] CVE-2017-10178: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require hum
nvd
CVE-2017-10123MEDIUMCVSS 4.3v12.1.3.0.02017-08-08
CVE-2017-10123 [MEDIUM] CVE-2017-10123: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2017-10063MEDIUMCVSS 4.8v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10063 [MEDIUM] CVE-2017-10063: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vu
nvd
CVE-2017-10148MEDIUMCVSS 5.8v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10148 [MEDIUM] CVE-2017-10148: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in
nvd
CVE-2017-3531HIGHCVSS 7.2v12.1.3.0.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3531 [HIGH] CVE-2017-3531: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Ser Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Servlet Runtime). Supported versions that are affected are 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in
nvd
CVE-2017-3506HIGHCVSS 7.4KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2017-04-24
CVE-2017-3506 [HIGH] CWE-78 CVE-2017-3506: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attac
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+3 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-7103MEDIUMCVSS 6.1v10.3.6.0.0v12.1.3.0.0+1 more2017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd
CVE-2017-5638CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2017-03-11
CVE-2017-5638 [CRITICAL] CWE-755 CVE-2017-5638: The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has in The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild i
nvd
CVE-2017-3248CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+6 more2017-01-27
CVE-2017-3248 [CRITICAL] CVE-2017-3248: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vul
cvelistv5nvd
CVE-2016-3551CRITICALCVSS 9.8v11.1.1.7.0v11.1.1.9.0+2 more2016-10-25
CVE-2016-3551 [CRITICAL] CVE-2016-3551: Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7. Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXWS Web Services Stack.
nvd
CVE-2016-5531CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2016-10-25
CVE-2016-5531 [CRITICAL] CVE-2016-5531: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices.
nvd
CVE-2016-5535CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+2 more2016-10-25
CVE-2016-5535 [CRITICAL] CVE-2016-5535: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd