Risk | High |
Patch available | YES |
Number of vulnerabilities | 25 |
CVE-ID | CVE-2021-29425 CVE-2020-13956 CVE-2018-1324 CVE-2019-10219 CVE-2022-21386 CVE-2022-21262 CVE-2022-21261 CVE-2022-21260 CVE-2022-21259 CVE-2022-21258 CVE-2022-21257 CVE-2020-11023 CVE-2022-21361 CVE-2020-2934 CVE-2022-21353 CVE-2022-21350 CVE-2022-21347 CVE-2022-21252 CVE-2021-44832 CVE-2021-27568 CVE-2022-21371 CVE-2020-5258 CVE-2022-21292 CVE-2021-4104 CVE-2022-21306 |
CWE-ID | CWE-22 CWE-20 CWE-835 CWE-79 CWE-94 CWE-502 |
Exploitation vector | Network |
Public exploit |
Public exploit code for vulnerability #12 is available. Public exploit code for vulnerability #21 is available. |
Vulnerable software Subscribe |
Oracle WebLogic Server Server applications / Application servers |
Vendor | Oracle |
Security Bulletin
This security bulletin contains information about 25 vulnerabilities.
EUVDB-ID: #VU52252
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29425
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error within the FileNameUtils.normalize method when processing directory traversal sequences, such as "//../foo", or "\..foo". A remote attacker can send a specially crafted request and verify files availability in the parent folder.
Install update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU47481
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-13956
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to insufficient validation of user-supplied input in Apache HttpClient. A remote attacker can pass request URIs to the library as java.net.URI object and force the application to pick the wrong target host for request execution.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU11170
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2018-1324
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to an error the ZipFile and ZipArchiveInputStream classes when handling malicious input. A remote attacker can send a specially crafted ZIP archive, trigger an infinite loop and cause the service to crash.
Install update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59717
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2019-10219
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Web Services (JBoss Enterprise Application Platform) component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.3.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59716
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21386
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Web Container component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59715
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21262
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59714
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21261
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59713
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21260
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59712
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21259
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59711
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21258
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59710
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21257
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU27519
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-11023
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when passing <option>
elements to jQuery’s DOM manipulation methods. A remote attacker can execute arbitrary JavaScript code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59709
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21361
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Sample apps component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU26918
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-2934
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Connector/J component in MySQL Connectors. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59708
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21353
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The vulnerability exists due to improper input validation within the Core component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to manipulate or delete data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.3.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59707
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21350
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The vulnerability exists due to improper input validation within the Core component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to manipulate or delete data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59706
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21347
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The vulnerability exists due to improper input validation within the Core component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to manipulate or delete data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59705
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21252
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59098
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-44832
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.3.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55372
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-27568
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to read data or crash the application.
The vulnerability exists due to improper input validation within the REST Services (netplex json-smart-v1) component in PeopleSoft Enterprise PeopleTools. A remote non-authenticated attacker can exploit this vulnerability to read data or crash the application.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.3.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59704
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21371
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing dashes in URI. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU30113
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-5258
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote authenticated user to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Cluster: Packaging (dojo) component in MySQL Cluster. A remote authenticated user can exploit this vulnerability to gain access to sensitive information.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59703
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-21292
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Samples component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.4.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU58977
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-4104
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in JMSAppender, when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution.
Note this issue only affects Log4j 1.2 when specifically configured to
use JMSAppender, which is not the default.
Install update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.2.1.3.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59700
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-21306
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Core component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle WebLogic Server: 12.1.3.0.0 - 14.1.1.0.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpujan2022.html?3219
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?