📦 Weblogic Server

by Oracle

🔍 What is Weblogic Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-21535

CRITICAL CVSS 9.8 Jan 21, 2025

CVE-2025-21535 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to remotely execute arbitrary code and completely compromise affected servers. The vulnerabil...

CVE-2024-21216

CRITICAL CVSS 9.8 Oct 15, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to fully compromise the server, leading to complete takeover. It affects WebL...

CVE-2024-21181

CRITICAL CVSS 9.8 Jul 16, 2024

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely compromise the server. Affected versions are 12.2.1.4....

CVE-2023-22089

CRITICAL CVSS 9.8 Oct 17, 2023

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely compromise the server. Affected versions are 12.2.1.4....

CVE-2023-22069

CRITICAL CVSS 9.8 Oct 17, 2023

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely compromise the server. It affects WebLogic Server vers...

CVE-2023-22072

CRITICAL CVSS 9.8 Oct 17, 2023

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely compromise the server. It affects WebLogic Server 12.2...

CVE-2022-21306

CRITICAL CVSS 9.8 Jan 19, 2022

CVE-2022-21306 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated attackers with network access via the T3 protocol to completely compromise the server. This affects Web...

CVE-2022-23305

CRITICAL CVSS 9.8 Jan 18, 2022

CVE-2022-23305 is an SQL injection vulnerability in Log4j 1.2.x's JDBCAppender that allows attackers to execute arbitrary SQL queries by injecting malicious strings into application inputs that get lo...

CVE-2021-35617

CRITICAL CVSS 9.8 Oct 20, 2021

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via IIOP to completely compromise the server. Affected versions include 12.1.3.0.0, 12.2.1.3....

CVE-2021-2108

CRITICAL CVSS 9.8 Jan 20, 2021

CVE-2021-2108 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated remote attackers to execute arbitrary code and completely compromise affected servers. The vulnerability...

CVE-2021-2075

CRITICAL CVSS 9.8 Jan 20, 2021

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers to remotely execute arbitrary code and completely compromise affected servers. It affects multiple supported vers...

CVE-2021-2064

CRITICAL CVSS 9.8 Jan 20, 2021

CVE-2021-2064 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated remote attackers to execute arbitrary code and completely compromise affected servers. This affects WebL...

CVE-2021-2047

CRITICAL CVSS 9.8 Jan 20, 2021

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via IIOP or T3 protocols to completely compromise the server. Affected versions include 10.3....

CVE-2021-1994

CRITICAL CVSS 9.8 Jan 20, 2021

An unauthenticated remote code execution vulnerability in Oracle WebLogic Server's Web Services component allows attackers to completely compromise affected servers via HTTP. This affects WebLogic Ser...

CVE-2020-14750

CRITICAL CVSS 9.8 Nov 2, 2020

CVE-2020-14750 is a critical remote code execution vulnerability in Oracle WebLogic Server's Administration Console. Unauthenticated attackers can exploit this via HTTP to completely compromise affect...

CVE-2020-14882

CRITICAL CVSS 9.8 Oct 21, 2020

CVE-2020-14882 is a critical remote code execution vulnerability in Oracle WebLogic Server's Administration Console. Unauthenticated attackers can exploit this via HTTP to completely compromise affect...

CVE-2020-14859

CRITICAL CVSS 9.8 Oct 21, 2020

CVE-2020-14859 is a critical remote code execution vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to completely compromise affected servers via IIOP or T3 protocols. Thi...

CVE-2020-14841

CRITICAL CVSS 9.8 Oct 21, 2020

CVE-2020-14841 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to remotely execute arbitrary code via the IIOP protocol. This affects multiple supported ver...

CVE-2020-14825

CRITICAL CVSS 9.8 Oct 21, 2020

CVE-2020-14825 is a critical remote code execution vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to completely compromise affected servers via IIOP or T3 protocols. Thi...

CVE-2025-61752

HIGH CVSS 7.5 Oct 21, 2025

An unauthenticated remote attacker can exploit this vulnerability in Oracle WebLogic Server via HTTP/2 to cause a denial of service, resulting in server crashes or hangs. This affects Oracle WebLogic ...

CVE-2025-30762

HIGH CVSS 7.5 Jul 15, 2025

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0, 14....

CVE-2025-21549

HIGH CVSS 7.5 Jan 21, 2025

This vulnerability allows unauthenticated attackers to cause a denial of service (DoS) on Oracle WebLogic Server 14.1.1.0.0 by sending specially crafted HTTP/2 requests. The attack can crash or hang t...

CVE-2024-21274

HIGH CVSS 7.5 Oct 15, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers to cause denial of service by crashing or hanging the server via HTTP requests. It affects WebLogic Server versions 12.2.1...

CVE-2024-21234

HIGH CVSS 7.5 Oct 15, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and ...

CVE-2024-21183

HIGH CVSS 7.5 Jul 16, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and ...

CVE-2024-21175

HIGH CVSS 7.5 Jul 16, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server's integrity. Attackers can create, delete, or modify critical data a...

CVE-2024-21006

HIGH CVSS 7.5 Apr 16, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and ...

CVE-2024-20927

HIGH CVSS 8.6 Feb 17, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server. It enables unauthorized creation, deletion, or modification of crit...

CVE-2024-20931

HIGH CVSS 7.5 Feb 17, 2024

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and ...

CVE-2023-22108

HIGH CVSS 7.5 Oct 17, 2023

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and ...

CVE-2023-21996

HIGH CVSS 7.5 Apr 18, 2023

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers to cause a denial of service (DoS) by crashing or hanging the server via HTTP requests. It affects WebLogic Server version...

CVE-2023-21979

HIGH CVSS 7.5 Apr 18, 2023

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 protocol to gain unauthorized access to sensitive data. It affects WebLogic Server versions...

CVE-2023-21964

HIGH CVSS 7.5 Apr 18, 2023

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 protocol to cause a denial of service by crashing or hanging the server. It affects WebLogi...

CVE-2022-21441

HIGH CVSS 7.5 Apr 19, 2022

CVE-2022-21441 is a denial-of-service vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to crash the server via T3/IIOP network protocols. Affected versions include 12.2.1....

CVE-2020-36518

HIGH CVSS 7.5 Mar 11, 2022

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, crashing the application. This affects any Java ap...

CVE-2022-21371

HIGH CVSS 7.5 Jan 19, 2022

CVE-2022-21371 is a local file inclusion vulnerability in Oracle WebLogic Server's web container that allows unauthenticated attackers with network access via HTTP to read arbitrary files on the serve...

CVE-2022-21292

HIGH CVSS 7.5 Jan 19, 2022

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to access sensitive data. It affects WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, spec...

CVE-2021-4104

HIGH CVSS 7.5 Dec 14, 2021

CVE-2021-4104 is a deserialization vulnerability in Log4j 1.2's JMSAppender that allows remote code execution when attackers can modify Log4j configuration files. This affects systems running Log4j 1....

CVE-2021-2351

HIGH CVSS 8.3 Jul 21, 2021

This vulnerability in Oracle Database's Advanced Networking Option allows attackers to bypass network encryption protections and potentially compromise the component. It affects Oracle Database Server...

CVE-2021-3450

HIGH CVSS 7.4 Mar 25, 2021

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects applications using OpenSSL 1.1.1h-1.1.1j that enable s...

CVE-2025-50073

MEDIUM CVSS 6.1 Jul 15, 2025

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server. It requires human interaction from someone other than the attacker ...

CVE-2025-50064

MEDIUM CVSS 4.8 Jul 15, 2025

This vulnerability in Oracle WebLogic Server allows authenticated high-privileged attackers to modify or read limited data through HTTP requests requiring user interaction. It affects WebLogic Server ...

CVE-2025-30753

MEDIUM CVSS 6.5 Jul 15, 2025

This vulnerability in Oracle WebLogic Server allows authenticated attackers with low privileges to cause a denial of service (DoS) by crashing or hanging the server via HTTP requests. It affects WebLo...

CVE-2020-8908

LOW CVSS 3.3 Dec 10, 2020

This vulnerability in Google Guava's createTempDir() method creates temporary directories with world-readable permissions on Unix-like systems, allowing any user on the same machine to potentially rea...