vulnerability
Oracle WebLogic: CVE-2021-23369 : Critical Patch Update
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Apr 12, 2021 | Apr 25, 2024 | Oct 16, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Apr 12, 2021
Added
Apr 25, 2024
Modified
Oct 16, 2025
Description
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Solutions
oracle-weblogic-apr-2024-cpu-12_2_1_4_0oracle-weblogic-apr-2024-cpu-14_1_1_0_0
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.