Skip to content

CVE-2023-22031 | WebLogic Server

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)..This CVE has a CVSS3.1 score of 4.4 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-22031
CVE StatePUBLISHED
BaseScore4.4
BaseSeverityMEDIUM
VectorStringCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
VersionNA

References for CVE-2023-22031 :
https://www.oracle.com/security-alerts/cpujul2023.html

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)HIGH
PrivilegesRequired(PR)HIGH
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)NONE
Availability(A)HIGH
Integrity(I)NONE