Sploitus

CVE-2022-21350

1 known exploit for CVE-2022-21350

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).

Affected products
Oracle Weblogic Server
Oracle Weblogic Server
= 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
3.6% (88th percentile)
NVD status
Modified
Published
2022-01-19
CVE-2022-21350 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-21350

Proof-of-concept code and exploit modules indexed by Sploitus