QID 150481

Date Published: 2022-03-09

QID 150481: Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2022)

Oracle WebLogic Server (formerly known as BEA WebLogic Server) is an application server for building and deploying enterprise applications and services.
The Oracle WebLogic Server component in Oracle Fusion Middleware for versions 12.2.1.4.0 and 14.1.1.0.0 has fixes for multiple vulnerabilities.

Affected Versions:
Oracle WebLogic Server, version(s) 12.2.1.4.0 and 14.1.1.0.0

QID Detection Logic:
The qid sends a "GET console/login/LoginForm.jsp" request to retrieve the WebLogic version installed.

NOTE: CVE-2022-21258 is only applicable for WebLogic Server 14.1.1.0.0

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise and takeover Oracle WebLogic Server.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released patches for these issues. Customers are advised to refer to Oracle - CPUJAN2022
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2022 URL Logo www.oracle.com/security-alerts/cpujan2022.html