S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-21371 Scanner

Detects 'Local File Inclusion' vulnerability in Oracle WebLogic Server affects v. 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
7
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-21371
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
12.1.3.0.0
Updated Aug 22, 2026View on NVD →
Detail

Oracle WebLogic Server is a Java application server that provides a platform for deploying, managing, and running enterprise Java applications. It is used by many organizations as a middleware technology to facilitate the communication between different systems and applications. Being an industry-leading product, the Oracle WebLogic Server is widely used by businesses across different sectors to build scalable and secure applications that can handle high volumes of transactions.

Recently, a critical vulnerability, identified as CVE-2022-21371, has been detected in the Oracle WebLogic Server. The vulnerability affects multiple versions of the software, including 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The vulnerability is easily exploitable and can be used by an unauthenticated attacker with network access via HTTP to compromise the Oracle WebLogic Server. 

If the vulnerability is exploited, it can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. The attacker can use the vulnerability to execute arbitrary code or perform actions that can cause system instability. The confidentiality of sensitive information can also be at risk if the vulnerability is not addressed on time.

At s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets. With the platform's pro features, users can get timely alerts about potential vulnerabilities in their software and systems, prioritize their patching efforts, and mitigate the risks associated with cybersecurity threats. The platform also provides actionable insights and recommendations to help users improve their security posture and protect their critical assets.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-21371 vulnerability, users can take the following precautions:

  • Install the latest patch released by Oracle to address the vulnerability
  • Restrict network access to the WebLogic Server only to trusted sources
  • Monitor the network traffic to detect any malicious activities
  • Implement proper access controls and authorization mechanisms to limit the privileges of users and processes
  • Regularly review and update the security configuration of the server

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.