Severity
High
Analysis summary
A deserialization vulnerability via XMLDecoder in Oracle WebLogic Server Web Services. This remote code execution vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.
Impact
Unauthorized system access
Affected Vendors
Oracle
Affected Products
- Oracle WebLogic Server 12.2.1.3
- Oracle WebLogic Server 10.3.6.0.0
- Oracle WebLogic Server 12.1.3.0.0
Remediation
Updates are available.