Junglewise Threat Intelligence

CVE-2024-21182: Oracle WebLogic Server unspecified vulnerability in Core component

CVE-2024-21182 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2026-06-01

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a vulnerability that allows unauthorized individuals to access sensitive data. An attacker can exploit this over the network without needing a username or password. This could lead to the exposure of critical business information or complete access to all data managed by the server.

Technical details

An unspecified vulnerability exists in the Core component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows the attacker to bypass security controls to gain unauthorized access to critical data or complete access to all data accessible by the WebLogic Server. While the vendor classifies this as an 'unspecified' vulnerability (CWE-noinfo), it is frequently associated with improper handling of serialized objects or protocol-specific parsing issues in the T3/IIOP stacks. Users should apply the July 2024 Oracle Critical Patch Update (CPU) to mitigate this risk.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2024-07-16: disclosed: Initial disclosure by Oracle
  • 2024-07-16: advisory: NVD published the CVE record
  • 2024-11-21: other: CVE record updated with enrichment data

Related threats