QID 150355
Date Published: 2021-08-16
QID 150355: Oracle WebLogic Server Multiple Vulnerabilities (APR-JUL 2021)
Oracle WebLogic Server (formerly known as BEA WebLogic Server) is an application server for building and deploying enterprise applications and services.
The Oracle WebLogic Server component in Oracle Fusion Middleware for versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 has fixes for multiple vulnerabilities.
Affected Versions:
Oracle WebLogic Server, version(s) 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0
QID Detection Logic:
The qid sends a "GET console/login/LoginForm.jsp" request to retrieve the WebLogic version installed.
NOTE: CVE-2021-2142 is only applicable for WebLogic Server 10.3.6.0.0
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise and takeover Oracle WebLogic Server .
- CPUAPR2021 -
www.oracle.com/security-alerts/cpuapr2021.html - CPUJUL2021 -
www.oracle.com/security-alerts/cpujul2021.html
CVEs related to QID 150355
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CPUAPR2021 |
|
||
| CPUJUL2021 |
|