QID 150788
Date Published: 2024-02-08
QID 150788: Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2024)
Oracle WebLogic Server (formerly known as BEA WebLogic Server) is an application server for building and deploying enterprise applications and services.
The Oracle WebLogic Server component in Oracle Fusion Middleware for versions 12.2.1.4.0 and 14.1.1.0.0 has fixes for multiple vulnerabilities.
Affected Versions:
Oracle WebLogic Server version 12.2.1.4.0
Oracle WebLogic Server version 14.1.1.0.0
QID Detection Logic:(Unauthenticated)
The QID sends a HTTP GET request to "console/login/LoginForm.jsp" endpoint to retrieve the WebLogic version installed.
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise and takeover Oracle WebLogic Server.
Solution
The vendor has released patches for these issues. Customers are advised to refer to Oracle - CPUJAN2024.
Vendor References
- CPUJAN2024 -
www.oracle.com/security-alerts/cpujan2024.html
CVEs related to QID 150788
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CPUJAN2024 |
|