Executive brief
An unspecified vulnerability in the WLS Core Components of Oracle WebLogic Server allows unauthenticated attackers to gain full control of the server via the IIOP protocol. Successful exploitation can result in a complete takeover of the affected Oracle Fusion Middleware instance.
Affected products
- Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
Timeline
- 2020-01-15: disclosed: NVD Published Date
- 2020-01-15: advisory: Oracle Critical Patch Update Advisory - January 2020
- 2023-11-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog