Executive brief
An unspecified vulnerability in the Console component of Oracle WebLogic Server allows high-privileged attackers with network access via HTTP to compromise the server. Successful exploitation can lead to a complete takeover of the affected Oracle WebLogic Server instance.
Affected products
- Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2020-10-21: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: CISA advisory publication date