← Vulnerability feed

Vulnerability record · CVE-2022-21371 · published 19 January 2022

CVE-2022-21371: Oracle WebLogic Server path traversal exposes local files

Oracle · Weblogic Server

Oracle WebLogic Server's Web Container component is affected by a path traversal (CWE-22) flaw in versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker with network access via HTTP can read files accessible to the WebLogic process, which may expose configuration, credentials or other critical data.

7.5 CVSS 3.1 High EPSS 93% · top 0.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable file disclosure with a very high EPSS score and a public exploit reference, though not in KEV.

What it is

Oracle WebLogic Server's Web Container component is affected by a path traversal (CWE-22) flaw in versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker with network access via HTTP can read files accessible to the WebLogic process, which may expose configuration, credentials or other critical data.

Impact

An attacker gains unauthorized read access to critical data or complete access to all data reachable by the WebLogic Server process. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any WebLogic HTTP listener on an affected version is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.92649, 99.8th percentile) and a public exploit reference exists (Packet Storm local file inclusion). No ransomware association is documented.

What to do

  • Apply the Oracle January 2022 Critical Patch Update for WebLogic Server; upgrade to a fixed release for your affected version line.
  • If patching cannot be immediate, restrict network access to WebLogic HTTP ports to trusted hosts only.
  • Run WebLogic under a least-privilege OS account so file reads are limited to non-sensitive paths.
  • Remove or rotate any credentials or secrets stored in files readable by the WebLogic process.
  • Monitor vendor advisories for updated guidance on affected versions.

Detection

  • Inspect WebLogic HTTP access logs for requests containing path traversal sequences (../, ..%2f, encoded variants) targeting file paths.
  • Alert on HTTP requests to WebLogic endpoints returning unusually large or file-like responses.
  • Monitor for reads of sensitive files (e.g., configuration, keystore, property files) by the WebLogic process user.
  • Correlate WebLogic access log entries with process-level file access telemetry on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21371 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2020-14750Oracle WebLogic Server Console unauthenticated remote code executionOracle WebLogic Server's Console component contains an easily exploitable flaw affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and …KEVEPSS 99%analysed9.8CVE-2020-14882Oracle WebLogic Server Console unauthenticated remote code executionThe Oracle WebLogic Server Console component contains an easily exploitable flaw that lets an unauthenticated attacker with network access take over …KEVEPSS 100%analysed9.8CVE-2020-14644Oracle WebLogic Server unauthenticated RCE via IIOP and T3Oracle WebLogic Server Core contains an easily exploitable flaw reachable over the network through IIOP and T3. An unauthenticated attacker can explo…KEVEPSS 95%analysed9.8CVE-2020-2883Oracle WebLogic Server Core unauthenticated remote code execution via IIOP/T3Oracle WebLogic Server Core contains an easily exploitable vulnerability reachable over the network through IIOP and T3. An unauthenticated attacker …KEVEPSS 95%analysed9.8CVE-2020-2551Oracle WebLogic Server IIOP Deserialization RCEOracle WebLogic Server contains an easily exploitable vulnerability in WLS Core Components reachable over IIOP. An unauthenticated network attacker c…KEVEPSS 93%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2018-2628Oracle WebLogic Server T3 deserialization allows unauthenticated remote takeoverOracle WebLogic Server contains a deserialization of untrusted data flaw (CWE-502) in the WLS Core Components, reachable over the T3 protocol. An una…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-21371), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.