Skip to content
COOEY

EXPOSURES › CVE-2024-21182

CVE-2024-21182

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-06-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-21182 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedransomware

Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols.

This unpatched vulnerability enables unauthenticated attackers to compromise WebLogic Server instances, posing a severe risk to DIB organizations relying on Oracle middleware for FedRAMP/NIST 800-171 compliance. Immediate patching and network segmentation are required to prevent unauthorized data access.

Shame score — While the vulnerability is actively exploited, it is a known issue with a public patch available, making it less avoidable than negligent vendor behavior.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized