Executive brief
Oracle WebLogic Server contains a deserialization vulnerability in the WLS Core Components. An unauthenticated attacker with network access via the T3 protocol can exploit this flaw to achieve a complete takeover of the server.
Affected products
- Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3
Timeline
- 2018-04-17: advisory: Initial Oracle Critical Patch Update (CPU) advisory published.
- 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog.