cbcvebase.

Oracle Weblogic Server vulnerabilities

313 known vulnerabilities affecting oracle/weblogic_server.

Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4

Vulnerabilities

Page 15 of 16
CVE-2018-11771P4MEDIUMCVSS 5.5v14.1.1.0.02018-08-16
CVE-2018-11771 [MEDIUM] CWE-835 CVE-2018-11771: When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17 When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service att
nvd
CVE-2018-1324P4MEDIUMCVSS 5.5v14.1.1.0.02018-03-16
CVE-2018-1324 [MEDIUM] CWE-835 CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compr A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2022-29577P4MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.0+1 more2022-04-21
CVE-2022-29577 [MEDIUM] CVE-2022-29577: OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. T OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.
nvd
CVE-2021-28170P4MEDIUMCVSS 5.3v14.1.1.0.02021-05-26
CVE-2021-28170 [MEDIUM] CWE-20 CVE-2021-28170: In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManag In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
nvd
CVE-2019-12400P4MEDIUMCVSS 5.5v12.2.1.4.0v14.1.1.0.02019-08-23
CVE-2019-12400 [MEDIUM] CWE-20 CVE-2019-12400: In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache S
nvd
CVE-2017-10063P4MEDIUMCVSS 4.8v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10063 [MEDIUM] CVE-2017-10063: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vu
nvd
CVE-2020-2550P4MEDIUMCVSS 5.1v10.3.6.0.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2550 [MEDIUM] CVE-2020-2550: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracl
nvd
CVE-2021-2033P4MEDIUMCVSS 4.3v12.1.3.0.0v12.2.1.3.0+2 more2021-01-20
CVE-2021-2033 [MEDIUM] CVE-2021-2033: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this v
nvd
CVE-2020-2869P4MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2869 [MEDIUM] CVE-2020-2869: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human in
nvd
CVE-2020-9488P4LOWCVSS 3.7v10.3.6.0.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2018-2902P4MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.02018-10-17
CVE-2018-2902 [MEDIUM] CVE-2018-2902: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Con Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Console). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2025-50064P4MEDIUMCVSS 4.8v12.2.1.4.0v14.1.1.0.0+1 more2025-07-15
CVE-2025-50064 [MEDIUM] CWE-269 CVE-2025-50064: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interacti
nvd
CVE-2017-10123P4MEDIUMCVSS 4.3v12.1.3.0.02017-08-08
CVE-2017-10123 [MEDIUM] CVE-2017-10123: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2019-2887P4MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.0+1 more2019-10-16
CVE-2019-2887 [MEDIUM] CVE-2019-2887: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability ca
nvd
CVE-2017-10334P4MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10334 [MEDIUM] CWE-200 CVE-2017-10334: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful atta
nvd
CVE-2020-2544P4MEDIUMCVSS 4.3v10.3.6.0.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2544 [MEDIUM] CVE-2020-2544: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human in
nvd
CVE-2019-2398P4MEDIUMCVSS 4.3v10.3.6.0v12.1.3.0+1 more2019-01-16
CVE-2019-2398 [MEDIUM] CVE-2019-2398: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Deployment). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2016-5601P4MEDIUMCVSS 6.3v12.1.3.0.0v12.2.1.0.0+1 more2016-10-25
CVE-2016-5601 [MEDIUM] CWE-284 CVE-2016-5601: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components.
nvd
CVE-2022-21616P4MEDIUMCVSS 5.2v12.2.1.3.0v12.2.1.4.0+1 more2022-10-18
CVE-2022-21616 [MEDIUM] CVE-2022-21616: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Cont Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Ser
nvd
CVE-2020-2547P4MEDIUMCVSS 4.8v10.3.6.0.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2547 [MEDIUM] CVE-2020-2547: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human in
nvd
Oracle Weblogic Server vulnerabilities | cvebase