Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
Tue, 04 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Unauthenticated Access to Oracle WebLogic Server Console Enables Data Exfiltration |
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle WebLogic Server Console Privilege Escalation Vulnerability | |
| Weaknesses | CWE-200 |
Fri, 24 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle WebLogic Server Console Privilege Escalation Vulnerability | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle weblogic Server |
|
| CPEs | cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle weblogic Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-25T03:55:59.747Z
Reserved: 2026-07-08T15:51:40.542Z
Link: CVE-2026-60527
Updated: 2026-07-24T19:09:36.555Z
Status : Analyzed
Published: 2026-07-21T22:17:52.400
Modified: 2026-07-31T21:15:54.550
Link: CVE-2026-60527
No data.
OpenCVE Enrichment
Updated: 2026-08-04T03:45:03Z