Oracle · Oracle Weblogic Server · CVE-2022-21453
**Name of the Vulnerable Software and Affected Versions**
Oracle WebLogic Server versions 12.2.1.3.0 through 12.2.1.4.0
Oracle WebLogic Server version 14.1.1.0.0
**Description**
The issue is related to a buffer read overflow in the Oracle WebLogic Server Console component. It can be exploited by a remote attacker using specially crafted HTTP requests, potentially allowing unauthorized read access or modification of data. Successful attacks require human interaction and may impact additional products.
**Recommendations**
For Oracle WebLogic Server versions 12.2.1.3.0 through 12.2.1.4.0, update to a version that includes the fix for this issue.
For Oracle WebLogic Server version 14.1.1.0.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Console component until a patch is available.