CVE-2016-5535 describes an unspecified vulnerability within Oracle WebLogic Server, impacting versions 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 of Oracle Fusion Middleware. This critical vulnerability, with a CVSS score of 9.8, allows remote attackers to compromise confidentiality, integrity, and availability without requiring user interaction or authentication. While no public exploit code or active exploitation has been confirmed, the vulnerability garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.3.6.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* | ||
12.1.3.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* | ||
12.2.1.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:* | ||
12.2.1.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Oracle WebLogic Server Commons DiskFileItem Remote File Manipulation
Nov 2, 2016[R1] Oracle WebLogic Server Commons DiskFileItem Remote File Manipulation
Nov 2, 2016[R1] Oracle WebLogic Server Commons DiskFileItem Remote File Manipulation
Nov 1, 2016[R1] Oracle WebLogic Server Commons DiskFileItem Remote File Manipulation
Nov 1, 2016