Oracle WebLogic Server 12.2.1.2

CPE Details

Oracle WebLogic Server 12.2.1.2
12.2.1.2
2017-05-02
19h28 +00:00
2018-01-10
15h38 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:oracle:weblogic_server:12.2.1.2:*:*:*:*:*:*:*

Informations

Vendor

oracle

Product

weblogic_server

Version

12.2.1.2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2018-3213 2018-10-16 23h00 +00:00 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Docker Images). The supported version that is affected is prior to Docker 12.2.1.3.20180913. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
7.5
Haute
CVE-2018-1258 2018-05-11 20h00 +00:00 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
8.8
Haute
CVE-2017-15707 2017-12-01 16h00 +00:00 In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
6.2
Moyen