Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 4 of 16
CVE-2021-2047P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2021-01-20
CVE-2021-2047 [CRITICAL] CVE-2021-2047: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2021-2075P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+3 more2021-01-20
CVE-2021-2075 [CRITICAL] CVE-2021-2075: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attack
nvd
CVE-2021-23450P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02021-12-17
CVE-2021-23450 [CRITICAL] CWE-1321 CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
nvd
CVE-2020-14859P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14859 [CRITICAL] CVE-2020-14859: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2010-2375P3MEDIUMCVSS 6.4PoCv10.3.2.0.0v10.3.3.0.02010-07-13
CVE-2010-2375 [MEDIUM] CVE-2010-2375: Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebL
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
nvd
CVE-2020-2546P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.02020-01-15
CVE-2020-2546 [CRITICAL] CVE-2020-2546: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Applicat
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2017-10137P2CRITICALCVSS 10.0v10.3.6.0.0v12.1.3.0.02017-08-08
CVE-2017-10137 [CRITICAL] CVE-2017-10137: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JND
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, att
nvd
CVE-2021-2108P2CRITICALCVSS 9.8v12.1.3.0.02021-01-20
CVE-2021-2108 [CRITICAL] CVE-2021-2108: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in take
nvd
CVE-2021-2064P2CRITICALCVSS 9.8v12.1.3.0.02021-01-20
CVE-2021-2064 [CRITICAL] CVE-2021-2064: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in take
nvd
CVE-2021-2136P2CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.3.0+2 more2021-04-22
CVE-2021-2136 [CRITICAL] CVE-2021-2136: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2021-35617P2CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.3.0+2 more2021-10-20
CVE-2021-35617 [CRITICAL] CVE-2021-35617: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherenc
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2021-2382P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2382 [CRITICAL] CVE-2021-2382: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attac
nvd
CVE-2021-2397P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2397 [CRITICAL] CVE-2021-2397: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks o
nvd
CVE-2019-2890P2HIGHCVSS 7.2v10.3.6.0.0v12.1.3.0.0+1 more2019-10-16
CVE-2019-2890 [HIGH] CVE-2019-2890: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can r
nvd
CVE-2017-10352P2CRITICALCVSS 9.9v10.3.6.0.0v12.1.3.0.0+3 more2017-10-19
CVE-2017-10352 [CRITICAL] CVE-2017-10352: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. W
nvd
CVE-2020-11987P2HIGHCVSS 8.2v12.2.1.3.0v12.2.1.4.0+1 more2021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-2801P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2801 [CRITICAL] CVE-2020-2801: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2020-2884P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2884 [CRITICAL] CVE-2020-2884: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2024-21181P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02024-07-16
CVE-2024-21181 [CRITICAL] CVE-2024-21181: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in t
nvd
CVE-2024-21216P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02024-10-15
CVE-2024-21216 [CRITICAL] CWE-862 CVE-2024-21216: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can res
nvd