What Happened?
A security vulnerability in Oracle's WebLogic Server is currently being actively exploited. The US IT security agency CISA is warning about the flaw and has added it to its "Known Exploited Vulnerabilities" catalog. US federal agencies have until June 4 to close the vulnerability. The flaw has been known since mid-2024, with Oracle providing a security update as part of its Critical Patch Update in July 2024.
The Details
The affected component is the "Core" of Oracle Fusion Middleware. Unauthenticated attackers can access and compromise vulnerable WebLogic servers over the network via the proprietary T3 and IIOP protocols. Oracle has not provided further details on the exact attack mechanisms.
Successful attacks can lead to unauthorized access to critical data or even complete access to all data available on the WebLogic server. The vulnerability is registered as CVE-2024-21182 and rated "high" with a CVSS score of 7.5.
Software versions Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 are considered vulnerable. Other, no longer supported versions may also be affected. As is customary, CISA has not disclosed details about the scope or nature of the ongoing attacks, meaning no indicators of compromise (IOCs) are available for IT teams to specifically search for.
Assessment
The active exploitation of a vulnerability that is already a year old reveals a recurring pattern: although patches are available, they are apparently not being widely applied in practice. Middleware components such as Oracle WebLogic Server in particular are often deeply integrated into corporate infrastructures and sometimes run for years without updates, because changes to production systems are considered risky.
This case fits into a recent surge of reports concerning actively exploited security vulnerabilities. Just this past Monday, it became known that a vulnerability in Palo Alto Networks' network operating system PAN-OS is also being actively exploited — there, attackers can bypass security measures, and this only about two weeks after the vulnerability became known and the manufacturer released a patch. This development illustrates that attackers are increasingly reacting faster once vulnerabilities become public or patches are released.
Practical Tips
- IT teams should immediately check whether their network topology includes Oracle WebLogic Server versions 12.2.1.4.0 or 14.1.1.0.0.
- Oracle's Critical Patch Update from July 2024 should be applied immediately if this has not already been done.
- Older, no-longer-supported WebLogic versions should also be reviewed and, if necessary, removed from production use or isolated.
- Access via the T3 and IIOP protocols should be restricted to trusted network segments wherever operationally feasible.
- In general: deployed software should be continuously kept up to date and protected, as reports of actively exploited security vulnerabilities are currently on the rise.
Outlook
Since CISA has not provided detailed information about the attacks, IT teams currently have no choice but to take a proactive approach through patch management and system hardening. Given the June 4 deadline for US federal agencies, it can be assumed that exploitation of the vulnerability could continue to increase if it is not closed promptly. Organizations outside the US federal government are not bound by this deadline, but should take the urgency of the warning just as seriously in order to avoid becoming targets of opportunistic attackers who systematically exploit known, unpatched vulnerabilities.