Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a vulnerability in its Web Services component. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive corporate data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.
Technical details
A vulnerability in the WLS - Web Services component of Oracle WebLogic Server allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized by a CVSS 3.1 score of 8.6, primarily impacting confidentiality. A 'scope change' (S:C) is noted, indicating that an exploit may impact components beyond the WebLogic Server itself. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 Critical Patch Update.