← back

CVE-2026-60201

HIGH · 8.1
No AI summary yet — the auto-summarizer runs every 10 minutes for top trending CVEs.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 3.1 breakdown

Exploitability 2.2 · Impact 5.9
vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected versions

  • oracle/weblogic_server
    • 12.2.1.4.0
    • 14.1.1.0.0
    • 14.1.2.0.0
    • 15.1.1.0.0

Weaknesses

Vendors

  • oracle

Products

  • weblogic_server