CVE-2025-50072

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Configurations

No configuration.

History

16 Jul 2025, 15:15

Type Values Removed Values Added
CWE CWE-284

16 Jul 2025, 14:58

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en el producto Oracle WebLogic Server de Oracle Fusion Middleware (componente: Core). Las versiones compatibles afectadas son 12.2.1.4.0, 14.1.1.0.0 y 14.1.2.0.0. Esta vulnerabilidad, fácilmente explotable, permite que un atacante no autenticado, con acceso a la infraestructura donde se ejecuta Oracle WebLogic Server, lo vulnere. Los ataques con éxito pueden resultar en actualizaciones, inserciones o eliminaciones no autorizadas de algunos datos accesibles de Oracle WebLogic Server. Puntuación base de CVSS 3.1: 4.0 (Afecta a la integridad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

15 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 20:15

Updated : 2025-07-16 15:15


NVD link : CVE-2025-50072

Mitre link : CVE-2025-50072

CVE.ORG link : CVE-2025-50072


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control