CVE-2021-2294: Medium severity oracle weblogic server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2294?
CVE-2021-2294 is considered to have a high severity rating due to its potential for unauthenticated remote exploitation.
How do I fix CVE-2021-2294?
To mitigate CVE-2021-2294, Oracle recommends applying the latest patches and updates for affected versions of WebLogic Server.
Which versions of WebLogic Server are affected by CVE-2021-2294?
CVE-2021-2294 affects WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.
Can CVE-2021-2294 be exploited remotely?
Yes, CVE-2021-2294 can be easily exploited by unauthenticated attackers with network access.
What type of vulnerability is CVE-2021-2294?
CVE-2021-2294 is classified as a core vulnerability in the Oracle WebLogic Server product.