Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle · WebLogic Server
Date added (CISA)
2024-09-18
Remediation due
2024-10-09
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.