PT-2024-1145 · Oracle · Oracle Weblogic Server

Published

2024-01-16

·

Updated

2024-11-29

·

CVE-2024-20927

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle WebLogic Server versions 12.2.1.4.0 through 14.1.1.0.0
Description The issue is related to insufficient input validation in the Core component of Oracle WebLogic Server, allowing an unauthenticated attacker with network access via HTTP to compromise the server. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle WebLogic Server accessible data. The vulnerability may significantly impact additional products.
Recommendations For Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-00461
CVE-2024-20927

Affected Products

Oracle Weblogic Server