Oracle WebLogic Server Vulnerability Lets Attackers Compromise the Server Remotely
ID: d681845e-39a7-56c4-ad9a-3ee7c3b75e7b
STIX ID: report--d681845e-39a7-56c4-ad9a-3ee7c3b75e7b
Feed Name: cybersecurityNews.com
Threat Score
A high-severity vulnerability (CVE-2024-21182) in Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0) allows unauthenticated remote exploitation over T3 and IIOP (CVSS 7.5). A public proof-of-concept has been released, increasing the risk to enterprise deployments; Oracle issued fixes in the July 2024 Critical Patch Update and organizations are advised to apply patches, restrict T3/IIOP access, monitor for exploitation, and harden configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
