Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Aug 2025 00:30:00 +0900


Thu, 10 Oct 2024 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2025-08-13T14:25:23.690Z

Reserved: 2016-12-06T00:00:00.000Z

Link: CVE-2017-3248

cve-icon Vulnrichment

Updated: 2025-08-13T14:25:23.690Z

cve-icon NVD

Status : Deferred

Published: 2017-01-27T22:59:02.553

Modified: 2025-08-13T15:15:29.313

Link: CVE-2017-3248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses