cbcvebase.

Oracle Corporation Weblogic Server vulnerabilities

190 known vulnerabilities affecting oracle_corporation/weblogic_server.

Total CVEs
190
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
19
Severity breakdown
CRITICAL51HIGH57MEDIUM81LOW1

Vulnerabilities

Page 1 of 10
CVE-2018-2628P1CRITICALCVSS 9.8KEVPoCv10.3.6.0v12.1.3.0+2 more2018-04-19
CVE-2018-2628 [CRITICAL] CWE-502 CVE-2018-2628: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-14882P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14882 [CRITICAL] CVE-2020-14882: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-14750P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-11-02
CVE-2020-14750 [CRITICAL] CVE-2020-14750: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2020-2883P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2883 [CRITICAL] CVE-2020-2883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulne
nvd
CVE-2020-14644P1CRITICALCVSS 9.8KEVPoCv12.2.1.3.0v12.2.1.4.0+1 more2020-07-15
CVE-2020-14644 [CRITICAL] CVE-2020-14644: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability c
nvd
CVE-2020-2551P1CRITICALCVSS 9.8KEVPoCv10.3.6.0.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2551 [CRITICAL] CVE-2020-2551: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2017-10271P1HIGHCVSS 7.5KEVPoCRansomwarev10.3.6.0.0v12.1.3.0.0+2 more2017-10-19
CVE-2017-10271 [HIGH] CWE-306 CVE-2017-10271: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks
nvd
CVE-2023-21839P1HIGHCVSS 7.5KEVPoCv12.2.1.3.0v12.2.1.4.0+1 more2023-01-18
CVE-2023-21839 [HIGH] CWE-502 CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability
nvd
CVE-2017-3506P1HIGHCVSS 7.4KEVPoCv10.3.6.0v12.1.3.0+3 more2017-04-24
CVE-2017-3506 [HIGH] CWE-78 CVE-2017-3506: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attac
nvd
CVE-2020-14883P1HIGHCVSS 7.2KEVPoCv10.3.6.0.0v12.1.3.0.0+3 more2020-10-21
CVE-2020-14883 [HIGH] CVE-2020-14883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of t
nvd
CVE-2024-21182P1HIGHCVSS 7.5KEVPoCv12.2.1.4.0v14.1.1.0.02024-07-16
CVE-2024-21182 [HIGH] CVE-2024-21182: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2729P1CRITICALCVSS 9.8ExploitedPoCRansomwarev10.3.6.0.0v12.1.3.0.0+1 more2019-06-19
CVE-2019-2729 [CRITICAL] CWE-284 CVE-2019-2729: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2018-2893P1CRITICALCVSS 9.8ExploitedPoCv10.3.6.0v12.1.3.0+2 more2018-07-18
CVE-2018-2893 [CRITICAL] CVE-2018-2893: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2022-21371P1HIGHCVSS 7.5ExploitedPoCv12.1.3.0.0v12.2.1.3.0+2 more2022-01-19
CVE-2022-21371 [HIGH] CWE-22 CVE-2022-21371: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Cont Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of
nvd
CVE-2018-2894P1CRITICALCVSS 9.8ExploitedPoCRansomwarev12.1.3.0v12.2.1.2+1 more2018-07-18
CVE-2018-2894 [CRITICAL] CVE-2018-2894: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerab
nvd
CVE-2021-2135P1CRITICALCVSS 9.8ExploitedPoCv12.2.1.3.0v12.2.1.4.0+1 more2021-04-22
CVE-2021-2135 [CRITICAL] CVE-2021-2135: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherenc Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vu
nvd
CVE-2019-2618P2MEDIUMCVSS 5.5ExploitedPoCv10.3.6.0.0v12.1.3.0.0+1 more2019-04-23
CVE-2019-2618 [MEDIUM] CVE-2019-2618: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vul
nvd
CVE-2021-2109P2HIGHCVSS 7.2ExploitedPoCv10.3.6.0.0v12.1.3.0.0+3 more2021-01-20
CVE-2021-2109 [HIGH] CVE-2021-2109: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console) Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of thi
nvd
CVE-2023-22069P1CRITICALCVSS 9.8ExploitedRansomwarev12.2.1.4.0v14.1.1.0.02023-10-17
CVE-2023-22069 [CRITICAL] CWE-306 CVE-2023-22069: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can res
nvd
CVE-2018-3245P1CRITICALCVSS 9.8PoCv10.3.6.0v12.1.3.0+1 more2018-10-17
CVE-2018-3245 [CRITICAL] CWE-502 CVE-2018-3245: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this v
nvd
1 / 10Next →