Vulnerabilities > Oracle > Weblogic Server

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-2867 Unspecified vulnerability in Oracle Weblogic Server 12.1.3.0.0/12.2.1.3.0/12.2.1.4.0
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).
network
low complexity
oracle
8.2
2020-04-15 CVE-2020-2829 Unspecified vulnerability in Oracle Weblogic Server 10.3.6.0.0
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Management Services).
network
low complexity
oracle
4.9
2020-04-15 CVE-2020-2828 Unspecified vulnerability in Oracle Weblogic Server 10.3.6.0.0
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Web Services).
network
low complexity
oracle
7.5
2020-04-15 CVE-2020-2811 Unspecified vulnerability in Oracle Weblogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
network
low complexity
oracle
6.1
2020-04-15 CVE-2020-2801 Unspecified vulnerability in Oracle Weblogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
network
low complexity
oracle
critical
9.8
2020-04-15 CVE-2020-2798 Unspecified vulnerability in Oracle Weblogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Web Services).
network
low complexity
oracle
7.2
2020-04-15 CVE-2020-2766 Unspecified vulnerability in Oracle Weblogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
network
low complexity
oracle
5.3
2020-04-07 CVE-2020-11620 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
network
high complexity
fasterxml debian netapp oracle CWE-502
8.1
2020-04-07 CVE-2020-11619 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
network
high complexity
fasterxml debian netapp oracle CWE-502
8.1
2020-03-31 CVE-2020-11113 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
network
low complexity
fasterxml debian netapp oracle CWE-502
8.8