Known vulnerabilities in Oracle WebLogic Server 12.2.1.2

Vendor: Oracle
Version: 12.2.1.2
Software CPE: cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 7
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Oracle WebLogic Server version 12.2.1.2 Oracle WebLogic Server 12.2.1.2 is affected by 7 vulnerabilities: 2 critical, 3 high, 2 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU48064 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-14750
CWE-94 High
Public exploit available
Exploited
- 02.11.2020 SB2020110201
SB2021012149
#VU18848 - Deserialization of Untrusted Data
CVE-2019-2729
CWE-502 Critical
Public exploit available
Exploited
- 20.06.2019 SB2019062001
SB2020042107
SB2020042370
and 6 more
#VU18354 - Deserialization of Untrusted Data
CVE-2019-2725
CWE-502 High
Public exploit available
Exploited
- 26.04.2019 SB2019042604
SB20200114132
SB20190716150
and 2 more
#VU13906 - Permissions, Privileges, and Access Controls
CVE-2018-2894
CWE-264 Low
Public exploit available
No
- 17.07.2018 SB2018071719
#VU10055 - Deserialization of Untrusted Data
CVE-2018-2628
CWE-502 High
Public exploit available
Exploited
- 17.01.2018 SB2018041912
#VU9816 - Deserialization of Untrusted Data
CVE-2017-3506
CWE-502 Critical
Public exploit available
Exploited
- 28.12.2017 SB2017042406
#VU9815 - Improper Access Control
CVE-2017-10271
CWE-284 Low
Public exploit available
Exploited
- 28.12.2017 SB2017101943