CVE-2021-2064
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. This vulnerability was discovered by Xiayu Zhang of Tencent Keen Security Lab and was included in Oracle's January 2021 Critical Patch Update (Oracle CPU).

Technical details

The vulnerability allows unauthenticated attackers with network access via IIOP or T3 protocols to compromise Oracle WebLogic Server. The vulnerability has been assigned a CVSS 3.1 Base Score of 9.8 (Critical) with Confidentiality, Integrity, and Availability impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (CVE MITRE).

Impact

Successful exploitation of this vulnerability can result in complete takeover of Oracle WebLogic Server. Due to the critical CVSS score of 9.8, the vulnerability poses a severe risk as it affects all three security aspects: confidentiality, integrity, and availability of the system (CVE MITRE).

Exploitability

The vulnerability is considered easily exploitable and requires no authentication or user interaction. An attacker only needs network access via IIOP or T3 protocols to attempt exploitation (Oracle CPU).

Mitigation and workarounds

Oracle addressed this vulnerability in the January 2021 Critical Patch Update. Users running affected versions of Oracle WebLogic Server 12.1.3.0.0 should apply the security patches provided in this update without delay (Oracle CPU).

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60702CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60977CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60698CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60696CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60699HIGH8.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management