PT-2007-1142 · Oracle · Oracle Weblogic Server

Published

2007-04-10

·

Updated

2020-08-24

·

CVE-2019-2452

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Oracle WebLogic Server versions 10.3.6.0, 12.1.3.0, 12.2.1.3
Description: The issue is related to inadequate access control in the WLS Core Components of Oracle WebLogic Server, allowing a remote attacker to gain unauthorized access to protected data or cause a denial of service using the HTTP protocol. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. Additionally, attackers can cause a hang or frequently repeatable crash of Oracle WebLogic Server.
Recommendations: For version 10.3.6.0, update to a newer version to mitigate the risk. For version 12.1.3.0, update to a newer version to mitigate the risk. For version 12.2.1.3, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the Oracle WebLogic Server via HTTP to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00383
CVE-2019-2452

Affected Products

Oracle Weblogic Server