cbcvebase.

Oracle Weblogic Server vulnerabilities

313 known vulnerabilities affecting oracle/weblogic_server.

Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4

Vulnerabilities

Page 2 of 16
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev12.2.1.3.0v12.2.1.4.0+1 more2021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2016-0638P1CRITICALCVSS 9.8ExploitedPoCv10.3.6.0.0v12.1.2.0.0+2 more2016-04-21
CVE-2016-0638 [CRITICAL] CVE-2016-0638: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
nvd
CVE-2020-11022P1MEDIUMCVSS 6.1ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 CVE-2020-11022: In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sa In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2021-4104P1HIGHCVSS 7.5ExploitedPoCv12.2.1.3.0v12.2.1.4.0+1 more2021-12-14
CVE-2021-4104 [HIGH] CWE-502 CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228.
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2021-2135P1CRITICALCVSS 9.8ExploitedPoCv12.2.1.3.0v12.2.1.4.0+1 more2021-04-22
CVE-2021-2135 [CRITICAL] CVE-2021-2135: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherenc Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vu
nvd
CVE-2020-9547P1CRITICALCVSS 9.8ExploitedPoCv12.2.1.3.0v12.2.1.4.02020-03-02
CVE-2020-9547 [CRITICAL] CWE-502 CVE-2020-9547: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
nvd
CVE-2020-9548P1CRITICALCVSS 9.8ExploitedPoCv12.2.1.3.0v12.2.1.4.02020-03-02
CVE-2020-9548 [CRITICAL] CWE-502 CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
nvd
CVE-2019-2618P2MEDIUMCVSS 5.5ExploitedPoCv10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2618 [MEDIUM] CVE-2019-2618: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2021-2109P2HIGHCVSS 7.2ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2021-01-20
CVE-2021-2109 [HIGH] CVE-2021-2109: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of thi
nvd
CVE-2015-9251P2MEDIUMCVSS 6.1ExploitedPoCv12.1.3.0v12.2.1.32018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2021-44832P1MEDIUMCVSS 6.6ExploitedRansomwarev12.2.1.3.0v12.2.1.4.0+1 more2021-12-28
CVE-2021-44832 [MEDIUM] CWE-20 CVE-2021-44832: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) a Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java
nvd
CVE-2025-21535P1CRITICALCVSS 9.8ExploitedRansomwarev12.2.1.4.0v14.1.1.0.02025-01-21
CVE-2025-21535 [CRITICAL] CWE-306 CVE-2025-21535: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can res
nvd
CVE-2023-22069P1CRITICALCVSS 9.8ExploitedRansomwarev12.2.1.4.0v14.1.1.0.02023-10-17
CVE-2023-22069 [CRITICAL] CWE-306 CVE-2023-22069: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can res
nvd
CVE-2017-3248P1CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+6 more2017-01-27
CVE-2017-3248 [CRITICAL] CVE-2017-3248: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2018-3245P1CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+1 more2018-10-17
CVE-2018-3245 [CRITICAL] CWE-502 CVE-2018-3245: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this v
nvd
CVE-2017-5645P1CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+3 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-3510P1CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+1 more2016-07-21
CVE-2016-3510 [CRITICAL] CVE-2016-3510: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586.
nvd
CVE-2008-3257P2CRITICALCVSS 10.0PoC≤ 10.32008-07-22
CVE-2008-3257 [CRITICAL] CWE-119 CVE-2008-3257: Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
nvd
CVE-2016-3586P2CRITICALCVSS 9.8PoCv10.3.6.0.0v12.1.3.0.0+1 more2016-07-21
CVE-2016-3586 [CRITICAL] CVE-2016-3586: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510.
nvd
Oracle Weblogic Server vulnerabilities | cvebase