Oracle · Oracle Weblogic Server · CVE-2022-21548
**Name of the Vulnerable Software and Affected Versions**
Oracle WebLogic Server versions 12.2.1.3.0 through 12.2.1.4.0
Oracle WebLogic Server version 14.1.1.0.0
**Description**
The issue exists due to insufficient input validation in the Core component of Oracle WebLogic Server. This allows a remote attacker to modify, add, or delete data, or cause a partial denial of service using the T3 and IIOP protocols. Successful attacks can result in unauthorized access to some of Oracle WebLogic Server's accessible data and the ability to cause a partial denial of service.
**Recommendations**
For Oracle WebLogic Server versions 12.2.1.3.0 and 12.2.1.4.0, update to a version that includes the fix for this issue.
For Oracle WebLogic Server version 14.1.1.0.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the T3 and IIOP protocols to minimize the risk of exploitation.