VDB
GSD-2023-21931
GSD-2023-21931
PUBLISHED
CVSS 7.5 HIGH
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | WebLogic Server | 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
Timeline
- Jun 9, 2023 PoC Published
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Oct 20, 2025 PoC Published
- Oct 23, 2025 PoC Published
- Apr 21, 2026 CVE Published