Oracle Weblogic Server vulnerabilities
313 known vulnerabilities affecting oracle/weblogic_server.
Total CVEs
313
CISA KEV
16
actively exploited
Public exploits
38
Exploited in wild
34
Severity breakdown
CRITICAL81HIGH98MEDIUM130LOW4
Vulnerabilities
Page 9 of 16
CVE-2020-10969P3HIGHCVSS 8.8v12.2.1.3.0v12.2.1.4.02020-03-26
CVE-2020-10969 [HIGH] CWE-502 CVE-2020-10969: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
nvd
CVE-2025-61752P3HIGHCVSS 7.5v14.1.1.0.0v14.1.2.0.02025-10-21
CVE-2025-61752 [HIGH] CWE-306 CVE-2025-61752: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in
nvd
CVE-2019-17359P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2016-0573P3HIGHCVSS 7.5v10.3.6.0.0v12.1.2.0.0+2 more2016-01-21
CVE-2016-0573 [HIGH] CVE-2016-0573: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Java Messaging Service.
nvd
CVE-2023-21838P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.0+1 more2023-01-18
CVE-2023-21838 [HIGH] CWE-400 CVE-2023-21838: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2023-21964P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.0+1 more2023-04-18
CVE-2023-21964 [HIGH] CWE-400 CVE-2023-21964: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can r
nvd
CVE-2023-21996P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.0+1 more2023-04-18
CVE-2023-21996 [HIGH] CWE-400 CVE-2023-21996: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnera
nvd
CVE-2020-11112P3HIGHCVSS 8.8v12.2.1.3.0v12.2.1.4.02020-03-31
CVE-2020-11112 [HIGH] CWE-502 CVE-2020-11112: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
nvd
CVE-2024-21260P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02024-10-15
CVE-2024-21260 [HIGH] CWE-863 CVE-2024-21260: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result
nvd
CVE-2024-21274P3HIGHCVSS 7.5≥ 12.2.1.4.0, ≤ 14.1.1.0.02024-10-15
CVE-2024-21274 [HIGH] CWE-120 CVE-2024-21274: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result
nvd
CVE-2020-10672P3HIGHCVSS 8.8v12.2.1.3.0v12.2.1.4.02020-03-18
CVE-2020-10672 [HIGH] CWE-502 CVE-2020-10672: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
nvd
CVE-2020-11619P3HIGHCVSS 8.1v12.2.1.3.0v12.2.1.4.02020-04-07
CVE-2020-11619 [HIGH] CWE-502 CVE-2020-11619: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
nvd
CVE-2020-5258P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02020-03-10
CVE-2020-5258 [HIGH] CWE-94 CVE-2020-5258: In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the ba
nvd
CVE-2016-0572P3HIGHCVSS 7.5v10.3.6.0.0v12.1.2.0.0+2 more2016-01-21
CVE-2016-0572 [HIGH] CVE-2016-0572: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Coherence Container.
nvd
CVE-2017-3531P3HIGHCVSS 7.2v12.1.3.0.0v12.2.1.0.0+2 more2017-04-24
CVE-2017-3531 [HIGH] CVE-2017-3531: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Ser
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Servlet Runtime). Supported versions that are affected are 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in
nvd
CVE-2020-10968P3HIGHCVSS 8.8v12.2.1.3.0v12.2.1.4.02020-03-26
CVE-2020-10968 [HIGH] CWE-502 CVE-2020-10968: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
nvd
CVE-2025-21549P3HIGHCVSS 7.5v14.1.1.0.02025-01-21
CVE-2025-21549 [HIGH] CWE-400 CVE-2025-21549: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2018-1000180P3HIGHCVSS 7.5v12.1.3.0.02018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2016-0574P3HIGHCVSS 7.5v10.3.6.0.0v12.1.2.0.0+2 more2016-01-21
CVE-2016-0574 [HIGH] CVE-2016-0574: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0577.
nvd
CVE-2016-0577P3HIGHCVSS 7.5v10.3.6.0.0v12.1.2.0.0+2 more2016-01-21
CVE-2016-0577 [HIGH] CVE-2016-0577: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0574.
nvd