Umbra Wiki cve cve/CVE-2024-21182
Back to wiki

CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability

provenance: imported · CVE: CVE-2024-21182

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Oracle
Product WebLogic Server
Date added 2026-06-01
Due date 2026-06-04
Ransomware campaign use Unknown

Description

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-21182
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog