Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Virtualbox | — | Upgrade Oracle VirtualBox to the latest version | Jul 17, 2025 | Apr 26, 2019 |
| Oracle Weblogic | — | Apply hotfix 29792735 for Oracle WebLogic Server versions between 12.1.3.0.0 - 12.1.3.0.190115.Apply the Patch Set Update (PSU) 29633432 for version 10.3.6.0.0.Apply hotfix 29792736 for Oracle WebLogic Server versions between 12.1.3.0.190116 - 12.1.3.0.190416.Apply the Patch Set Update (PSU) 29633448 for version 12.1.3.0.0.Apply hotfix 29800003 for Oracle WebLogic Server versions between 10.3.6.0.190116 - 10.3.6.0.190416.Apply hotfix 29800002 for Oracle WebLogic Server versions between 10.3.6.0.0 - 10.3.6.0.190416. | Apr 29, 2019 | Apr 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub