First published: Wed Oct 17 2018(Updated: )
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =12.2.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3201 is classified as a critical vulnerability due to its potential impact on Oracle WebLogic Server.
To fix CVE-2018-3201, apply the latest security patches provided by Oracle for the WebLogic Server version 12.2.1.3.
Exploitation of CVE-2018-3201 allows an unauthenticated attacker to compromise Oracle WebLogic Server, potentially leading to unauthorized access and data breaches.
CVE-2018-3201 affects Oracle WebLogic Server version 12.2.1.3.0.
Yes, CVE-2018-3201 is considered easily exploitable, allowing attackers with network access via T3 to compromise the server.