


Perceptive Security
SOC/SIEM Consultancy

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogi…
Published:
1 June 2026 at 00:00:00
Alert date:
1 June 2026 at 18:04:01
Source:
cisa.gov
Enterprise Applications, Web Technologies
Oracle WebLogic Server contains an unspecified vulnerability (CVE-2024-21182) that allows unauthenticated attackers with network access via T3 or IIOP protocols to compromise the server. Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. This vulnerability poses a high risk due to the lack of authentication requirements and potential for complete data compromise. The vulnerability was addressed in Oracle's July 2024 Critical Patch Update.
Technical details
Mitigation steps:
Affected products:
Oracle WebLogic Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2024-21182
https://www.oracle.com/security-alerts/cpujul2024.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
