QID 87482

Date Published: 2022-02-17

QID 87482: Oracle WebLogic Server Multiple Vulnerabilities (Log4Shell) (Doc_ID_2828556.1)

Oracle WebLogic Server (formerly known as BEA WebLogic Server) is an application server for building and deploying enterprise applications and services.
The Oracle WebLogic Server component in Oracle Fusion Middleware for versions,, and has fixes for multiple vulnerabilities.

Affected Versions:
Oracle WebLogic Server, version(s), and

QID Detection Logic (Authenticated):
Operating System: Linux
This QID checks to see if Oracle WebLogic Server process is listening on any of the TCP ports. If so, for version 12.x it gets the "Oracle_Home" path, navigates to that directory and reads "registry.xml" and the patch files found in the directory "Oracle_Home"\inventory\patches to check if the installed version is patched.
QID Detection Logic (Authenticated):
Operating System: Windows
For affected 12.x version
The QID checks the "Oracle_Home" path with help of the registry key "HKLM\Software\Oracle". The QID verifies if the affected WebLogic version is installed on the host and then checks if the corresponding patch is applied or not.

Patch IDs checked:
WebLogic Server - Patch 33416881, Patch 33691226
WebLogic Server - Patch 33416868, Patch 33691226
WebLogic Server - Patch 33412599, Patch 33691226
QID Detection Logic (Unauthenticated) :
The qid sends a "GET console/login/LoginForm.jsp" request to retrieve the WebLogic version installed.

Successful exploitation of this vulnerability could lead to remote code execution (RCE) on the target.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The vendor has released patches for these issues. Customers are advised to refer to Doc_ID_2828556.1 for detailed information.

    CVEs related to QID 87482

    Software Advisories
    Advisory ID Software Component Link
    Doc_ID_2828556.1 URL Logo support.oracle.com/knowledge/Oracle%20Cloud/2828556_1.html#REF_TEXT