Knox CVE Database
/
CVE-2024-21182
High
7.5

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

Added to the CISA KEV catalog:
June 1, 2026

Overview

Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 contain a flaw in the Core component that allows an unauthenticated remote attacker to read sensitive data by sending crafted requests over the T3 or IIOP protocols. No credentials or user interaction are required. A successful attack can expose critical application data or everything accessible to the WebLogic process, making any deployment with T3 or IIOP ports reachable from untrusted networks a direct target.

Vulnerability details

Affected vendor
Oracle
Affected product
WebLogic Server
Weakness type (CWE)

WebLogic's T3 and IIOP protocols are remote object communication channels used for Java EE application access and inter-component messaging. Both protocols accept inbound connections before authentication is established, and the Core component's handling of those early-stage messages contains a flaw that permits data disclosure. The precise sub-mechanism, whether improper access control, a protocol-level parsing error, or another class of weakness, is not specified in available sources, but the consequence is that the server exposes data to callers who have not authenticated.


An attacker with network access to the T3 or IIOP listening port sends crafted protocol messages to the affected server. No credentials are needed and no user interaction is required on the target. A successful exchange returns critical data or the full set of data accessible to the WebLogic process, which in enterprise deployments commonly includes application configuration, credentials stored in data sources, and business data held in connected databases. The only hard precondition is that the T3 or IIOP port is reachable from the attacker's network position.

Severity and impact

7.5
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor WebLogic server logs and network flow records for T3 (default port 7001) or IIOP connections originating from hosts outside the defined application-tier or client IP ranges; legitimate T3/IIOP peers are typically a bounded set of known application servers or admin hosts.
  • Review WebLogic audit logs for large or repeated data-retrieval operations associated with connections that have no corresponding application-layer authentication record, particularly from external or unexpected source addresses where no prior session history exists.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 4, 2026

Additional hardening

  • Apply Oracle's July 2024 Critical Patch Update for WebLogic Server 12.2.1.4.0 and 14.1.1.0.0; consult the vendor advisory listed in References for patch availability documents and installation instructions.
  • Restrict T3 and IIOP port access using network ACLs or firewall rules to allow only known, trusted application-tier hosts; these protocols have no legitimate use case from arbitrary internet sources.
  • If T3 or IIOP access is not required by deployed applications, disable those protocol channels in the WebLogic Server configuration to eliminate the attack surface entirely.
  • Place WebLogic administration and managed server ports behind a network segment boundary so that any exploitation attempt must first cross a controlled perimeter, reducing the pool of potential attackers.

Key dates

Published (NVD)
July 16, 2024
Added to CISA KEV
June 1, 2026
Remediation deadline
June 4, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2024-21182 affect my FedRAMP authorization?

If Oracle WebLogic Server runs inside your authorization boundary, yes. CVE-2024-21182 is listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 4, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can already see. Your options now are to remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2024-21182?

Knox does not patch Oracle WebLogic Server for you. Remediation is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that support your documentation for the next assessment. Applying the fix is yours to own. Managing your compliance posture while you work through it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2024-21182. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2024-21182's remediation deadline of June 4, 2026 has passed. What happens now?

If CVE-2024-21182 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing it out and documenting why the deadline slipped is what keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.