Known vulnerabilities in Oracle WebLogic Server 12.2.1.2
Vendor:
Oracle
Software:
Oracle WebLogic Server
Version:
12.2.1.2
Software CPE:
cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*
Website:
https://www.oracle.com
Total vulnerabilities:
7
Public exploits:
7
Known exploited (KEV):
6
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU48064 - Improper Control of Generation of Code ('Code Injection') CVE-2020-14750 |
CWE-94 | High | - | 02.11.2020 |
SB2020110201 SB2021012149 |
||
| #VU18848 - Deserialization of Untrusted Data CVE-2019-2729 |
CWE-502 | Critical | - | 20.06.2019 |
SB2019062001 SB2020042107 SB2020042370 and 6 more |
||
| #VU18354 - Deserialization of Untrusted Data CVE-2019-2725 |
CWE-502 | High | - | 26.04.2019 |
SB2019042604 SB20200114132 SB20190716150 and 2 more |
||
| #VU13906 - Permissions, Privileges, and Access Controls CVE-2018-2894 |
CWE-264 | Low | - | 17.07.2018 |
SB2018071719 |
||
| #VU10055 - Deserialization of Untrusted Data CVE-2018-2628 |
CWE-502 | High | - | 17.01.2018 |
SB2018041912 |
||
| #VU9816 - Deserialization of Untrusted Data CVE-2017-3506 |
CWE-502 | Critical | - | 28.12.2017 |
SB2017042406 |
||
| #VU9815 - Improper Access Control CVE-2017-10271 |
CWE-284 | Low | - | 28.12.2017 |
SB2017101943 |