CVE-2026-34315: Medium severity Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34315?
CVE-2026-34315 is considered to be easily exploitable, posing a significant risk to affected Oracle WebLogic Server versions.
How do I fix CVE-2026-34315?
To remediate CVE-2026-34315, it is recommended to apply the latest security patch provided by Oracle for the affected WebLogic Server versions.
Which versions of Oracle WebLogic Server are affected by CVE-2026-34315?
CVE-2026-34315 affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Can CVE-2026-34315 be exploited remotely?
Yes, CVE-2026-34315 allows unauthenticated attackers with network access via HTTP to exploit the vulnerability.
What is the impact of CVE-2026-34315 on my systems?
The impact of CVE-2026-34315 can include unauthorized access and potential compromise of sensitive data on vulnerable systems.