PT-2025-4257 · Oracle · Oracle Weblogic Server
Published
2025-01-21
·
Updated
2026-01-27
·
CVE-2025-21535
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
The vulnerable software is Oracle WebLogic Server, specifically the Core component of Oracle Fusion Middleware.
The affected versions are 12.2.1.4.0 and 14.1.1.0.0.
This issue allows an unauthenticated attacker to remotely compromise a WebLogic server via T3 or IIOP protocols, potentially leading to a server takeover.
An exploit for this issue is available, and it's estimated that over 2.7 million services may be vulnerable.
The issue can be exploited through insufficient filtering of incoming data through the T3 and IIOP protocols, allowing for remote code execution.
More information about the exploit and affected systems can be found at the vendor's advisory.
#OracleWebLogicServer #Cybersecurity #Exploit #T3 #IIOP #OracleFusionMiddleware #ServerTakeover #infosec #oracle
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Weblogic Server