Cyber Resilience

CVE-2021-2394

Oracle Weblogic Server 10.3.6.0.0 … 14.1.1.0.0

High EPSS
Published
21 July 2021
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.77 99.5th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2021-2394 is a critical-severity an unspecified weakness vulnerability in Oracle Weblogic Server. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle…

more

WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
Unauthenticated network exploit via T3/IIOP leads to full server takeover.
T1068 Exploitation for Privilege Escalation Privilege Escalationconfidence: HIGH
Remote code execution vulnerability enables privilege escalation to full control.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-22072Same product: Oracle Weblogic Server
CVE-2018-3191Same product: Oracle Weblogic Server
CVE-2024-20927Same product: Oracle Weblogic Server
CVE-2026-35298Same product: Oracle Weblogic Server
CVE-2026-60202Same product: Oracle Weblogic Server
CVE-2026-60203Same product: Oracle Weblogic Server
CVE-2017-10271Same product: Oracle Weblogic Server
CVE-2024-21216Same product: Oracle Weblogic Server
CVE-2026-60196Same product: Oracle Weblogic Server
CVE-2020-14841Same product: Oracle Weblogic Server

Affected Assets

oracle
weblogic server
10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References