Executive brief
Oracle WebLogic Server contains an OS command injection vulnerability in the Web Services subcomponent. An unauthenticated attacker can execute arbitrary code via specially crafted HTTP requests containing malicious XML documents, potentially leading to complete compromise of the server data.
Affected products
- Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, 12.2.1.2
Timeline
- 2017-04-18: patched: Oracle Critical Patch Update Advisory - April 2017
- 2024-06-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog