SecBoard
Zurück zur CVE-Übersicht

CVE-2026-21962

CRITICAL(10.0)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Risk Signal Score68/100 — HOCH
  • CVSS 10 — Kritisch
  • EPSS 42%
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

42.0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

10

Technische Schwere

SecBoard-Einordnung

CVE-2026-21962 betrifft den Oracle HTTP Server und das Oracle Weblogic Server Proxy Plug-in. Es handelt sich um eine leicht ausnutzbare Schwachstelle, die einem nicht authentifizierten Angreifer mit Netzwerkzugriff über HTTP ermöglicht, die betroffenen Produkte zu kompromittieren. Erfolgreiche Angriffe können zu unautorisiertem Erstellen, Löschen oder Modifizieren kritischer Daten sowie zu unautorisiertem Zugriff auf diese Daten führen, mit potenziellen Auswirkungen auf zusätzliche Produkte.

Diese Schwachstelle ist als kritisch einzustufen, mit einem CVSS-Score von 10.0. Die Exploit-Wahrscheinlichkeit () liegt bei 43%, und die Schwachstelle wird aktiv ausgenutzt, wie die Aufnahme in den KEV-Katalog bestätigt. Dies unterstreicht die Dringlichkeit der Bedrohung und das hohe Risiko für betroffene Systeme.

Security-Teams sollten umgehend alle betroffenen Instanzen des Oracle HTTP Servers und des Oracle Weblogic Server Proxy Plug-ins priorisieren und entsprechende Sicherheitsupdates oder Mitigationen anwenden. Eine schnelle Reaktion ist aufgrund der aktiven Ausnutzung und der hohen Kritikalität unerlässlich, um potenzielle Datenkompromittierungen zu verhindern.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Betroffene Produkte

  • cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:http_server:14.1.1.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.1.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.2.0.0:*:*:*:*:*:*:*

In diesen Analysen erwähnt

Referenzen