Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Oracle WebLogic Vulnerability Exploited in the Wild

The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.

Oracle

CISA is warning organizations that an Oracle WebLogic vulnerability patched nearly two years ago is being exploited in the wild.

The security hole, tracked as CVE-2024-21182, was patched by Oracle in the Java application server with its July 2024 CPU. The software giant’s advisory shows that the flaw was discovered and reported independently by several researchers.

Several proof-of-concept (PoC) exploits targeting CVE-2024-21182 have been made publicly available since the vulnerability’s existence came to light, but CISA appears to be the first to warn about its in-the-wild exploitation.

CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities (KEV) catalog on June 1, instructing federal agencies to address it by June 4.

The flaw can be leveraged by remote, unauthenticated hackers to compromise vulnerable Oracle WebLogic Server instances.

“Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data,” the agency noted in its KEV entry.

Advertisement. Scroll to continue reading.

There does not appear to be any information on attacks exploiting the vulnerability.

CISA’s KEV catalog includes a dozen other WebLogic Server flaws. The majority are vulnerabilities with CVEs assigned in 2020 or earlier, but most were added to the KEV catalog several years after Oracle patched them.

Related: Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Related: Oracle Patches 450 Vulnerabilities With April 2026 CPU

Related: Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability

Related: Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.