CVE-2024-21182
KEVlargeUnauthenticated Data Exposure in Oracle WebLogic Server via T3/IIOP
CISA: Oracle WebLogic Server Unspecified Vulnerability
CVE-2024-21182 is a vulnerability in the Core component of Oracle WebLogic Server (part of Oracle Fusion Middleware) affecting supported releases 12.2.1.4.0 and 14.1.1.0.0. It is easily exploited by an unauthenticated attacker who has network reachability to the server over the T3 or IIOP protocols, with no credentials or user interaction required. A successful attack grants unauthorized access to critical data, potentially complete access to all data accessible to Oracle WebLogic Server, which is reflected in the confidentiality-only CVSS 3.1 base score of 7.5 (C:H/I:N/A:N). Any organization running an affected WebLogic version, especially where T3/IIOP listeners are reachable from the internet or from less-trusted network zones, is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-01, and its EPSS score of 74.2% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known.
What to do: Apply the Oracle WebLogic security patch that fixes CVE-2024-21182 (delivered in Oracle's July 2024 Critical Patch Update) on versions 12.2.1.4.0 and 14.1.1.0.0, or upgrade to a patched release; as an interim mitigation, restrict T3/IIOP listener access to trusted hosts and networks. US federal agencies must follow BOD 22-01 timelines, and all defenders should hunt for exploitation activity given the KEV listing on 2026-06-01.
| Oracle WebLogic Server (Core component, Oracle Fusion Middleware) | 12.2.1.4.0 and 14.1.1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Affected
- Oracle WebLogic Server
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- weblogic server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N