VDB

GSD-2023-21931

GSD-2023-21931 PUBLISHED CVSS 7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Oracle CorporationWebLogic Server12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Timeline

  • Jun 9, 2023 PoC Published
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Oct 20, 2025 PoC Published
  • Oct 23, 2025 PoC Published
  • Apr 21, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›