Oracle Weblogic Server vulnerabilities

306 known vulnerabilities affecting oracle/weblogic_server.

Total CVEs
306
CISA KEV
15
actively exploited
Public exploits
31
Exploited in wild
22
Severity breakdown
CRITICAL81HIGH92MEDIUM129LOW4

Vulnerabilities

Page 6 of 16
CVE-2021-29425MEDIUMCVSS 4.8v12.1.3.0.0v12.2.1.3.0+2 more2021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2021-3450HIGHCVSS 7.4v12.2.1.4.0v14.1.1.0.02021-03-25
CVE-2021-3450 [HIGH] CWE-295 CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation
nvd
CVE-2021-21350CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.3.0+2 more2021-03-23
CVE-2021-21350 [CRITICAL] CWE-434 CVE-2021-21350: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist lim
nvd
CVE-2021-21347CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.3.0+2 more2021-03-23
CVE-2021-21347 [CRITICAL] CWE-434 CVE-2021-21347: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2020-11987HIGHCVSS 8.2v12.2.1.3.0v12.2.1.4.0+1 more2021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2021-27568MEDIUMCVSS 5.9v12.2.1.3.0v12.2.1.4.0+1 more2021-02-23
CVE-2021-27568 [MEDIUM] CWE-754 CVE-2021-27568: An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. A An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
nvd
CVE-2020-28491HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.0+1 more2021-02-18
CVE-2020-28491 [HIGH] CWE-770 CVE-2020-28491: This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
nvd
CVE-2021-2047CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+1 more2021-01-20
CVE-2021-2047 [CRITICAL] CVE-2021-2047: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2021-1994CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.02021-01-20
CVE-2021-1994 [CRITICAL] CVE-2021-1994: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result
nvd
CVE-2021-2075CRITICALCVSS 9.8v10.3.6.0.0v12.1.3.0.0+3 more2021-01-20
CVE-2021-2075 [CRITICAL] CVE-2021-2075: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attack
nvd
CVE-2021-2108CRITICALCVSS 9.8v12.1.3.0.02021-01-20
CVE-2021-2108 [CRITICAL] CVE-2021-2108: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in take
nvd
CVE-2021-2064CRITICALCVSS 9.8v12.1.3.0.02021-01-20
CVE-2021-2064 [CRITICAL] CVE-2021-2064: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in take
nvd
CVE-2021-2109HIGHCVSS 7.2ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2021-01-20
CVE-2021-2109 [HIGH] CVE-2021-2109: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of thi
nvd
CVE-2021-2018HIGHCVSS 8.3v12.2.1.3.02021-01-20
CVE-2021-2018 [HIGH] CVE-2021-2018: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attack
nvd
CVE-2021-2033MEDIUMCVSS 4.3v12.1.3.0.0v12.2.1.3.0+2 more2021-01-20
CVE-2021-2033 [MEDIUM] CVE-2021-2033: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Com Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this v
nvd
CVE-2021-1995MEDIUMCVSS 6.5v10.3.6.0.0v12.1.3.0.02021-01-20
CVE-2021-1995 [MEDIUM] CVE-2021-1995: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in
nvd
CVE-2021-1996LOWCVSS 2.4v10.3.6.0.0v12.1.3.0.02021-01-20
CVE-2021-1996 [LOW] CVE-2021-1996: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a perso
nvd
CVE-2020-8908LOWCVSS 3.3v14.1.1.0.02020-12-10
CVE-2020-8908 [LOW] CWE-378 CVE-2020-8908: A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with a A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to
nvd
CVE-2020-13956MEDIUMCVSS 5.3v12.2.1.4.0v14.1.1.0.02020-12-02
CVE-2020-13956 [MEDIUM] CVE-2020-13956: Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority co Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
nvd
CVE-2020-14750CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-11-02
CVE-2020-14750 [CRITICAL] CVE-2020-14750: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks
nvd