cbcvebase.

Oracle Weblogic Server vulnerabilities

313 known vulnerabilities affecting oracle/weblogic_server.

Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4

Vulnerabilities

Page 5 of 16
CVE-2019-2646P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2646 [CRITICAL] CVE-2019-2646: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerabi
nvd
CVE-2019-2645P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2645 [CRITICAL] CVE-2019-2645: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2020-14687P2CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.0+1 more2020-07-15
CVE-2020-14687 [CRITICAL] CVE-2020-14687: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability c
nvd
CVE-2016-5531P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2016-10-25
CVE-2016-5531 [CRITICAL] CVE-2016-5531: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices.
nvd
CVE-2016-3499P3CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.0.02016-07-21
CVE-2016-3499 [CRITICAL] CVE-2016-3499: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0 and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container.
nvd
CVE-2019-2856P2CRITICALCVSS 9.8v12.2.1.3.02019-07-23
CVE-2019-2856 [CRITICAL] CVE-2019-2856: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: App Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). Supported versions that are affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can re
nvd
CVE-2019-2658P2CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.02019-04-23
CVE-2019-2658 [CRITICAL] CVE-2019-2658: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2023-22089P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02023-10-17
CVE-2023-22089 [CRITICAL] CVE-2023-22089: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in t
nvd
CVE-2016-5535P3CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+2 more2016-10-25
CVE-2016-5535 [CRITICAL] CVE-2016-5535: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2018-3197P2CRITICALCVSS 9.8v12.1.3.0.02018-10-17
CVE-2018-3197 [CRITICAL] CVE-2018-3197: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in tak
nvd
CVE-2018-3201P2CRITICALCVSS 9.8v12.2.1.3.02018-10-17
CVE-2018-3201 [CRITICAL] CVE-2018-3201: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in tak
nvd
CVE-2023-22072P2CRITICALCVSS 9.8v12.2.1.3.02023-10-17
CVE-2023-22072 [CRITICAL] CWE-306 CVE-2023-22072: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeove
nvd
CVE-2021-3450P3HIGHCVSS 7.4v12.2.1.4.0v14.1.1.0.02021-03-25
CVE-2021-3450 [HIGH] CWE-295 CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation
nvd
CVE-2019-16942P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvd
CVE-2019-10086P3HIGHCVSS 7.3v10.3.6.0.02019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2019-17531P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-12
CVE-2019-17531 [CRITICAL] CWE-502 CVE-2019-17531: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it i
nvd
CVE-2019-16943P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-01
CVE-2019-16943 [CRITICAL] CWE-502 CVE-2019-16943: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to m
nvd
CVE-2016-8610P3HIGHCVSS 7.5v10.3.6.0.0v12.1.3.0.0+2 more2017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2022-23457P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.0+1 more2022-04-25
CVE-2022-23457 [CRITICAL] CWE-22 CVE-2022-23457: ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control l ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow
nvd
CVE-2026-35303P2HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.02026-06-17
CVE-2026-35303 [HIGH] CWE-306 CVE-2026-35303: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supp Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of
nvd
Oracle Weblogic Server vulnerabilities | cvebase