Executive brief
Oracle WebLogic Server, a platform used for building and deploying enterprise applications, contains a vulnerability in its management console. An attacker could trick a legitimate user into performing an action that allows the attacker to take full control of the server. This could lead to the theft of sensitive data, service outages, or the compromise of other connected business systems.
Technical details
This vulnerability is classified as an Open Redirect (CWE-601) within the Console component of Oracle WebLogic Server. It is reachable via the network over HTTP and does not require prior authentication. However, exploitation is considered difficult as it requires human interaction (User Interaction: Required) from a person other than the attacker. A successful exploit results in a scope change (Scope: Changed), potentially allowing the attacker to compromise the entire WebLogic Server instance and impact additional integrated products. The vulnerability affects versions 12.2.1.4.0 and 14.1.1.0.0. Oracle has released security updates to address this issue.
Affected products
- Oracle Corporation WebLogic Server 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle Corporation
- 2026-06-17: advisory: NVD record published