Skip to content
COOEY

FAIL › dossier

WebLogic Server

PRODUCT

· dossier confidence 20%

Oracle WebLogic Server is a widely deployed enterprise application server with a severe and recurring security track record. It is plagued by critical and high-severity vulnerabilities, most notably remote code execution (RCE) flaws that are frequently exploitable via its T3 and IIOP protocols. Compliance officers must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching via Oracle's Critical Patch Updates, and rigorous vulnerability management.

PROFILE
CategoryEnterprise Application ServerWhat they doOracle WebLogic Server is an enterprise application server and Java EE application server used for building and deploying enterprise applications. Websitehttps://www.oracle.com/weblogic/ ↗
SECURITY POSTURE

WebLogic Server has a historically poor security posture, characterized by a high frequency of critical and high-severity vulnerabilities, particularly remote code execution (RCE) flaws exploitable via T3/IIOP protocols. The product has been actively exploited in the wild, requiring continuous patching via Oracle's Critical Patch Updates (CPU) and strict network lockdown of admin ports.

Notable failures
  • CVE-2017-10271: Critical RCE allowing arbitrary code execution
  • CVE-2019-2725: Critical injection vulnerability in Web Services
  • CVE-2020-14644: High RCE via deserialization over T3/IIOP
  • CVE-2020-14882: High RCE allowing unauthenticated remote code execution
  • CVE-2024-21182: High vulnerability allowing unauthenticated remote access to critical data
Patterns: Repeated unpatched RCE vulnerabilities exploitable via T3/IIOP protocols; Deserialization of untrusted data leading to remote code execution; Injection vulnerabilities in core components like Web Services and Console
FAILURE HISTORY · 16
DATEEVENTSEVSUMMARY
2022-02-10 CVE-2017-10271 critical Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks.
2024-06-03 CVE-2017-3506 high Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests.
2021-11-03 CVE-2020-14882 high Oracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild.
2021-11-03 CVE-2020-14750 high Oracle WebLogic Server suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild.
2023-05-01 CVE-2023-21839 high Oracle WebLogic Server T3/IIOP RCE vulnerability exploited in the wild
2022-09-08 CVE-2018-2628 high Oracle WebLogic Server RCE due to unpatched vulnerability
2022-01-10 CVE-2019-2725 critical Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.
2021-11-03 CVE-2020-14883 high Oracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability.
2021-11-03 CVE-2015-4852 high Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild.
2025-01-07 CVE-2020-2883 high Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.
2024-09-18 CVE-2020-14644 high Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.
2026-06-01 CVE-2024-21182 high Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols.
2026-08-18 CVE-2026-60977 critical CVE-2026-60977: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
2020-03-02 CVE-2020-9548 critical CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2020-03-02 CVE-2020-9546 critical CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2019-04-26 CVE-2019-2725 critical CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
Open questions: Current patch cycle SLA for WebLogic Server · Specific Oracle support contract requirements for WebLogic Server
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:27:18.379968+00:00