CVE-2025-21549

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 770

Summary

CVE-2025-21549 is a vulnerability affecting Oracle WebLogic Server version 14.1.1.0.0 of Oracle Fusion Middleware. This easily exploitable issue allows unauthenticated attackers to cause a hang or frequent crash of the server via HTTP/2 network access. The impact of successful attacks is primarily on server availability, with a CVSS Base Score of 7.5. Attackers can leverage this vulnerability to carry out a Denial of Service (DoS) attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle WebLogic Server

Affected Vendors

  • Oracle Corp