Executive brief
An injection vulnerability in the Web Services subcomponent of Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server. Successful exploitation can lead to a complete takeover of the affected Oracle WebLogic Server instance.
Affected products
- Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0
- Oracle Agile PLM 9.3.3, 9.3.4, 9.3.5
- Oracle Communications Converged Application Server 5.1, 7.0, 7.1
- Oracle PeopleSoft Enterprise PeopleTools 8.56, 8.57, 8.58
Timeline
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog