Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 6 of 16
CVE-2026-35311P2HIGHCVSS 8.8v12.2.1.4.0v14.1.2.0.02026-06-17
CVE-2026-35311 [HIGH] CWE-284 CVE-2026-35311: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of Web
nvd
CVE-2024-21006P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02024-04-16
CVE-2024-21006 [HIGH] CWE-306 CVE-2024-21006: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result
nvd
CVE-2024-21175P3CRITICALCVSS 9.1v12.2.1.4.0v14.1.1.0.02024-07-16
CVE-2024-21175 [CRITICAL] CWE-787 CVE-2024-21175: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result
nvd
CVE-2016-3551P3CRITICALCVSS 9.8v11.1.1.7.0v11.1.1.9.0+2 more2016-10-25
CVE-2016-3551 [CRITICAL] CVE-2016-3551: Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.
Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXWS Web Services Stack.
nvd
CVE-2016-3505P3HIGHCVSS 8.8v10.3.6.0.0v12.1.3.0.0+1 more2016-10-25
CVE-2016-3505 [HIGH] CVE-2016-3505: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to JavaServer Faces.
nvd
CVE-2019-17195P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02019-10-15
CVE-2019-17195 [CRITICAL] CWE-755 CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, wh
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
nvd
CVE-2019-14540P3CRITICALCVSS 9.8v12.2.1.3.02019-09-15
CVE-2019-14540 [CRITICAL] CWE-502 CVE-2019-14540: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
nvd
CVE-2018-1000613P3CRITICALCVSS 9.8v12.2.1.32018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2019-20330P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02020-01-03
CVE-2019-20330 [CRITICAL] CWE-502 CVE-2019-20330: FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
nvd
CVE-2018-1258P3HIGHCVSS 8.8v10.3.6.0v12.1.3.0+2 more2018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2020-14820P3HIGHCVSS 7.5v10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14820 [HIGH] CVE-2020-14820: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2021-2157P3HIGHCVSS 7.5v10.3.6.0.0v12.1.3.0.0+2 more2021-04-22
CVE-2021-2157 [HIGH] CVE-2021-2157: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2021-40690P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02021-09-19
CVE-2021-40690 [HIGH] CWE-200 CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
nvd
CVE-2017-10147P3HIGHCVSS 8.6v10.3.6.0.0v12.1.3.0.0+2 more2017-08-08
CVE-2017-10147 [HIGH] CVE-2017-10147: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Cor
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Or
nvd
CVE-2024-20927P3HIGHCVSS 8.6v12.2.1.4.0v14.1.1.0.02024-02-17
CVE-2024-20927 [HIGH] CWE-284 CVE-2024-20927: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, at
nvd
CVE-2019-2891P3HIGHCVSS 8.1v10.3.6.0.0v12.1.3.0.0+1 more2019-10-16
CVE-2019-2891 [HIGH] CVE-2019-2891: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can re
nvd
CVE-2020-14639P3HIGHCVSS 7.5v12.1.3.0.0v12.2.1.3.0+2 more2020-07-15
CVE-2020-14639 [HIGH] CVE-2020-14639: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample a
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vuln
nvd
CVE-2023-22101P3HIGHCVSS 8.1v12.2.1.4.0v14.1.1.0.02023-10-17
CVE-2023-22101 [HIGH] CWE-306 CVE-2023-22101: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul
nvd
CVE-2020-2798P3HIGHCVSS 7.2v10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2798 [HIGH] CVE-2020-2798: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Web
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of thi
nvd
CVE-2019-16335P3CRITICALCVSS 9.8v12.2.1.3.02019-09-15
CVE-2019-16335 [CRITICAL] CVE-2019-16335: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
nvd