Vulnerability record · CVE-2022-21371 · published 19 January 2022
CVE-2022-21371: Oracle WebLogic Server path traversal exposes local files
Oracle · Weblogic Server
Oracle WebLogic Server's Web Container component is affected by a path traversal (CWE-22) flaw in versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker with network access via HTTP can read files accessible to the WebLogic process, which may expose configuration, credentials or other critical data.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable file disclosure with a very high EPSS score and a public exploit reference, though not in KEV.
What it is
Oracle WebLogic Server's Web Container component is affected by a path traversal (CWE-22) flaw in versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker with network access via HTTP can read files accessible to the WebLogic process, which may expose configuration, credentials or other critical data.
Impact
An attacker gains unauthorized read access to critical data or complete access to all data reachable by the WebLogic Server process. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any WebLogic HTTP listener on an affected version is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.92649, 99.8th percentile) and a public exploit reference exists (Packet Storm local file inclusion). No ransomware association is documented.
What to do
- Apply the Oracle January 2022 Critical Patch Update for WebLogic Server; upgrade to a fixed release for your affected version line.
- If patching cannot be immediate, restrict network access to WebLogic HTTP ports to trusted hosts only.
- Run WebLogic under a least-privilege OS account so file reads are limited to non-sensitive paths.
- Remove or rotate any credentials or secrets stored in files readable by the WebLogic process.
- Monitor vendor advisories for updated guidance on affected versions.
Detection
- Inspect WebLogic HTTP access logs for requests containing path traversal sequences (../, ..%2f, encoded variants) targeting file paths.
- Alert on HTTP requests to WebLogic endpoints returning unusually large or file-like responses.
- Monitor for reads of sensitive files (e.g., configuration, keystore, property files) by the WebLogic process user.
- Correlate WebLogic access log entries with process-level file access telemetry on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpujan2022.html | Vendor Advisory |
| http://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpujan2022.html | Vendor Advisory |
Track CVE-2022-21371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21371), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.