Executive brief
A vulnerability in the WLS Security subcomponent of Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or HTTP to compromise the server. Successful exploitation can lead to remote code execution and complete takeover of the affected WebLogic Server instance.
Affected products
- Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0
Timeline
- 2017-10-17: advisory: Original Oracle Critical Patch Update advisory published
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-10: disclosed: NVD publication date