logo

Oracle WebLogic Server Vulnerability Lets Attackers Compromise the Server Remotely

ID: d681845e-39a7-56c4-ad9a-3ee7c3b75e7b

STIX ID: report--d681845e-39a7-56c4-ad9a-3ee7c3b75e7b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A high-severity vulnerability (CVE-2024-21182) in Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0) allows unauthenticated remote exploitation over T3 and IIOP (CVSS 7.5). A public proof-of-concept has been released, increasing the risk to enterprise deployments; Oracle issued fixes in the July 2024 Critical Patch Update and organizations are advised to apply patches, restrict T3/IIOP access, monitor for exploitation, and harden configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.