QID 150473
Date Published: 2022-02-23
QID 150473: Oracle WebLogic Server Denial of Service Vulnerability (CVE-2021-35620)
Oracle WebLogic Server is a robust, highly performant, and scalable application server for building and deploying both enterprise Java EE and Jakarta EE applications.
The installed version of Oracle WebLogic Server allow unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
Affected versions:
Oracle WebLogic Server, version(s) 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0
QID Detection Logic:
The QID sends a "GET console/login/LoginForm.jsp" request to retrieve the WebLogic version installed.
Successful exploitation of the vulnerability can allow an attacker to cause a hang or frequently repeatable crash (DOS) of Oracle WebLogic Server.
- CPUOCT2021 -
www.oracle.com/security-alerts/cpuoct2021.html
CVEs related to QID 150473
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CPUOCT2021 |
|