PT-2023-9842 · Oracle · Oracle Weblogic Server

·

CVE-2024-21182

·

Published

2023-12-07

·

Updated

2026-06-24

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle WebLogic Server version 12.2.1.4.0 Oracle WebLogic Server version 14.1.1.0.0
Description A flaw in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware, is caused by insufficient input validation and a post-deserialization issue. This allows an unauthenticated remote attacker with network access to compromise the server via T3 or IIOP protocols. Successful exploitation can lead to unauthorized access to critical data, complete access to all accessible server data, or remote code execution. There is evidence of active exploitation in the wild, with threat actors targeting internet-exposed servers to deploy ransomware, steal data, or install crypto-miners.
Recommendations Apply the July 2024 Critical Patch Update for version 12.2.1.4.0. Apply the July 2024 Critical Patch Update for version 14.1.1.0.0. As a temporary mitigation, block external access to T3 and IIOP protocols (default port 7001) and restrict exposure to trusted networks only.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00584
CVE-2024-21182
ORACLEWEBLOGIC_CVE2024_21182

Affected Products

Oracle Weblogic Server