
Cloud Vulnerability DB
A community-led vulnerabilities database
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. This vulnerability was discovered by Xiayu Zhang of Tencent Keen Security Lab and was included in Oracle's January 2021 Critical Patch Update (Oracle CPU).
The vulnerability allows unauthenticated attackers with network access via IIOP or T3 protocols to compromise Oracle WebLogic Server. The vulnerability has been assigned a CVSS 3.1 Base Score of 9.8 (Critical) with Confidentiality, Integrity, and Availability impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (CVE MITRE).
Successful exploitation of this vulnerability can result in complete takeover of Oracle WebLogic Server. Due to the critical CVSS score of 9.8, the vulnerability poses a severe risk as it affects all three security aspects: confidentiality, integrity, and availability of the system (CVE MITRE).
The vulnerability is considered easily exploitable and requires no authentication or user interaction. An attacker only needs network access via IIOP or T3 protocols to attempt exploitation (Oracle CPU).
Oracle addressed this vulnerability in the January 2021 Critical Patch Update. Users running affected versions of Oracle WebLogic Server 12.1.3.0.0 should apply the security patches provided in this update without delay (Oracle CPU).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."