Skip to main content

Oracle WebLogic Remote Code Execution Vulnerability

Last Update Date: 29 Apr 2019 Release Date: 26 Apr 2019 4963 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Oracle WebLogic server, a remote user can exploit this vulnerability to trigger Remote Code Execution on the targeted system.

 

Updated 29-4-2019: there is a patch release from vendor. 

Note: Proof Of Concept Exploit Code Is Publicly Available

 


Impact

  • Remote Code Execution

System / Technologies affected

  • Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0

 


Solutions

Updated 29-4-2019: there is a patch release from vendor

 

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link