QID 150477

Date Published: 2022-03-07

QID 150477: Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2021)

Oracle WebLogic Server is a robust, highly performant, and scalable application server for building and deploying both enterprise Java EE and Jakarta EE applications.

Oracle WebLogic Server contains multiple vulnerabilities:
CVE-2021-35552: Vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.

CVE-2021-35617: Vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server.

Affected versions:
Oracle WebLogic Server, version(s) 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0

QID Detection Logic:
The QID sends a "GET console/login/LoginForm.jsp" request to retrieve the WebLogic version installed.

Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released patches for these issues. Customers are advised to refer to Oracle - CPUOCT2021
    Vendor References

    CVEs related to QID 150477

    Software Advisories
    Advisory ID Software Component Link
    CPUOCT2021 URL Logo www.oracle.com/security-alerts/cpuoct2021.html