Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 29633448 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 29633432 for version 10.3.6.0.0.Apply hotfix 29792735 for Oracle WebLogic Server versions between 12.1.3.0.0 - 12.1.3.0.190115.Apply the Patch Set Update (PSU) 29814665 for version 12.2.1.3.0.Apply hotfix 29792736 for Oracle WebLogic Server versions between 12.1.3.0.190116 - 12.1.3.0.190416.Apply hotfix 29800003 for Oracle WebLogic Server versions between 10.3.6.0.190116 - 10.3.6.0.190416.Apply hotfix 29921455 for Oracle WebLogic Server versions between 12.2.1.3.190116 - 12.2.1.3.190416.Apply hotfix 29800002 for Oracle WebLogic Server versions between 10.3.6.0.0 - 10.3.6.0.190416. | Jun 19, 2019 | Jun 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub