Executive brief
Oracle WebLogic Server is a Java application server used to run enterprise applications and web services in corporate environments. An unauthenticated network attacker can exploit a vulnerability in the Web Container component to remotely execute code and fully compromise the server, potentially affecting other connected systems and applications. This is a critical issue requiring immediate patching.
Technical details
This vulnerability in the Web Container component of Oracle WebLogic Server is easily exploitable and requires no authentication or user interaction. An unauthenticated attacker with network access can send a specially crafted HTTP request to trigger the flaw and achieve remote code execution. The vulnerability has scope change, meaning successful exploitation may impact additional products beyond WebLogic Server itself. The affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Patches are expected to be available through Oracle's security update process.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed