ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-21182CVE-2020-2883

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2883
Unauthenticated RCE in Oracle WebLogic Server via T3/IIOP

CVE-2020-2883 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle WebLogic Server that is reachable over the network via the T3 and IIOP protocols. An attacker with network access to a WebLogic listener can trigger the flaw without credentials or user interaction, and successful exploitation results in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact. The supported affected releases are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Oracle rates the flaw CVSS 9.8 (Critical), and it carries a very high EPSS of 94.9% (100th percentile), indicating near-certain near-term exploitation likelihood. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 amid active exploitation, with reports of hackers targeting WebLogic servers and the flaw included in Oracle's January 2025 patch cycle.

Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server — Oracle's January 2025 patch release includes WebLogic fixes, and the affected releases (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0) must be patched per vendor instructions. Until patched, restrict network access to the T3 and IIOP listeners (e.g., firewall them to trusted hosts only), prioritize internet-facing instances, and hunt for signs of exploitation. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.895% KEV
  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
largetens of thousands of internet-exposed WebLogic instances
CVE-2024-21182
Unauthenticated Data Exposure in Oracle WebLogic Server via T3/IIOP

CVE-2024-21182 is a vulnerability in the Core component of Oracle WebLogic Server (part of Oracle Fusion Middleware) affecting supported releases 12.2.1.4.0 and 14.1.1.0.0. It is easily exploited by an unauthenticated attacker who has network reachability to the server over the T3 or IIOP protocols, with no credentials or user interaction required. A successful attack grants unauthorized access to critical data, potentially complete access to all data accessible to Oracle WebLogic Server, which is reflected in the confidentiality-only CVSS 3.1 base score of 7.5 (C:H/I:N/A:N). Any organization running an affected WebLogic version, especially where T3/IIOP listeners are reachable from the internet or from less-trusted network zones, is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-01, and its EPSS score of 74.2% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known.

Do: Apply the Oracle WebLogic security patch that fixes CVE-2024-21182 (delivered in Oracle's July 2024 Critical Patch Update) on versions 12.2.1.4.0 and 14.1.1.0.0, or upgrade to a patched release; as an interim mitigation, restrict T3/IIOP listener access to trusted hosts and networks. US federal agencies must follow BOD 22-01 timelines, and all defenders should hunt for exploitation activity given the KEV listing on 2026-06-01.

7.574% KEV
  • Oracle WebLogic Server (Core component, Oracle Fusion Middleware) 12.2.1.4.0 and 14.1.1.0.0
largetens of thousands of internet-exposed WebLogic servers (≈40,000–70,000 in public scans), with a far larger internal installed base
Full article243 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle WebLogic flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Palo Alto Networks PAN-OS flaw, tracked as CVE-2024-21182 (CVSS score of 7.5), to its Known Exploited Vulnerabilities (KEV) catalog.

The CVE-2024-21182 flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker can exploit the issue remotely over the T3 or IIOP protocols to gain unauthorized access to sensitive information stored on affected servers.

Successful exploitation could allow attackers to access critical data or potentially obtain full access to all data available through the compromised WebLogic Server instance.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by June 4, 2026.

In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency added another Oracle WebLogic Server flaw, tracked as CVE-2020-2883 (CVSS score 9.8),to its Known Exploited Vulnerabilities (KEV) catalog. An unauthenticated attacker with network access via IIOP, T3 can exploit the issue to compromise Oracle WebLogic Server.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193027/security/u-s-cisa-adds-oracle-weblogic-flaw-to-its-known-exploited-vulnerabilities-catalog.html