Oracle WebLogic Server Vulnerability CVE-2024-21182 Under Active Exploitation (heise.de)
0xBASE INTEL BRIEF
- CVE-2024-21182 (CVSS 7.5) in Oracle WebLogic Server actively exploited.
- CISA adds to KEV catalog; deadline for US agencies: June 4, 2026.
- Patches available since July 2024; administrators urged to update.
"CISA added a known vulnerability in Oracle WebLogic Server (CVE-2024-21182, CVSS 7.5) to its Known Exploited Vulnerabilities catalog. Unauthenticated attackers can fully compromise affected servers via T3/IIOP protocols. Versions 12.2.1.4.0 and 14.1.1.0.0 are affected. US federal agencies must patch by June 4, 2026. No IOCs disclosed."
#CVE-2024-21182
#Oracle WebLogic
#CISA KEV
no comments yet.