Executive brief
A critical vulnerability has been identified in the Oracle WebLogic Server Proxy Plug-in, a component used to connect third-party web servers to WebLogic application environments. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive data or modify critical system information. Because this component acts as a bridge, a successful attack could potentially compromise other connected systems and data across the corporate infrastructure.
Technical details
This vulnerability affects the WebLogic Server Proxy Plug-in for Third-Party Web Servers within Oracle Fusion Middleware. It is characterized by a CVSS score of 10.0 due to a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the plug-in. The attack vector is network-based via HTTP, requires no authentication (PR:N), and no user interaction (UI:N). Successful exploitation allows for the unauthorized creation, deletion, or modification of all data accessible to the plug-in, as well as complete confidentiality loss of that data. Affected versions include 15.1.1.0.0 of the plug-in and specific versions of Oracle HTTP Server.
Affected products
- Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0
- Oracle Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update
- 2026-07-21: disclosed