Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wangze

Researcher fromCodesafe Team of Legendsec at Qi
#42893of 53,624
6.1Total CVSS
Vulnerabilities · 1
PT-2022-3117
6.1
2022-04-19
Oracle · Oracle Weblogic Server · CVE-2022-21453
**Name of the Vulnerable Software and Affected Versions** Oracle WebLogic Server versions 12.2.1.3.0 through 12.2.1.4.0 Oracle WebLogic Server version 14.1.1.0.0 **Description** The issue is related to a buffer read overflow in the Oracle WebLogic Server Console component. It can be exploited by a remote attacker using specially crafted HTTP requests, potentially allowing unauthorized read access or modification of data. Successful attacks require human interaction and may impact additional products. **Recommendations** For Oracle WebLogic Server versions 12.2.1.3.0 through 12.2.1.4.0, update to a version that includes the fix for this issue. For Oracle WebLogic Server version 14.1.1.0.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Console component until a patch is available.