CVE-2022-21353
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceOracle WebLogic Server contains a vulnerability in its Core component where the T3 protocol improperly handles certain requests, allowing unauthenticated remote attackers to perform unauthorized data modifications (insert/update/delete) and cause partial denial of service. The vulnerability affects versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data= 12.2.1.3.0= 12.2.1.4.0= 14.1.1.0.0CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- Low
- Availability
- Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify installed WebLogic Server versionLog into the WebLogic Administration Console, navigate to the domain or server status page, or check the inventory file (typically in $ORACLE_HOME/oraInventory/ContentsXML/inventory.xml). Compare the installed version to 12.2.1.3.0, 12.2.1.4.0, or 14.1.1.0.0.Affected if The installed version exactly matches 12.2.1.3.0, 12.2.1.4.0, or 14.1.1.0.0
-
Verify T3 protocol is enabledIn WebLogic Administration Console, go to the server's Configuration > General tab and check for 'Enable T3' or 'Enable IIOP' settings. Alternatively, check the domain config.xml file for <server> entries containing <t3-enabled>true</t3-enabled> or the default T3 listener port (typically 7001) is open.Affected if T3 protocol is enabled on any listening server in the domain (this is the default state for unpatched installations)
-
Confirm T3 listener is network-accessibleCheck firewall rules and network configuration to determine if the T3 port (default 7001 for admin server, or configured managed server ports) accepts external connections. Use 'netstat -an | grep 7001' or port scanning tools to verify the listener is bound to a reachable interface.Affected if The T3 port is bound to a non-localhost address and accessible from untrusted networks (not restricted to localhost or VPN-only)
-
Check for recent Oracle Critical Patch UpdatesReview Oracle's patch inventory applied to the WebLogic installation. In the Oracle Inventory directory ($ORACLE_HOME/oraInventory), examine applied patches or check the WebLogic patch directory (usually $ORACLE_HOME/utils/bsu or $ORACLE_HOME/opatch). Look for patches from January 2022 CPU or later.Affected if No CPU patches from January 2022 or later have been applied, leaving the T3 vulnerability unmitigated
You are affected if your WebLogic Server version is exactly 12.2.1.3.0, 12.2.1.4.0, or 14.1.1.0.0 AND the T3 protocol is enabled and accessible on your network.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedApply Oracle's January 2022 Critical Patch Update (CPU) or later to Oracle WebLogic Server. If T3 protocol is not required, consider restricting T3/IIOP listener access at the network level as a compensating control.
Upgrade to the latest patch set of WebLogic Server 12.2.1.x or 14.1.1.x that includes the security fix from Oracle's CPU releases
- Apply the Oracle Critical Patch Update (CPU) that addresses CVE-2022-21353. Check Oracle's January 2022 Critical Patch Update and subsequent updates for this vulnerability fix.
- If direct patching is not feasible, consider upgrading to a later supported version of WebLogic Server within the same major release line (12.2.1.x or 14.1.1.x) that includes the security fix.
- As a mitigation, restrict network access to the T3/IIOP protocols by configuring WebLogic Server to disable T3 and IIOP or by using network segmentation/firewall rules to limit exposure to trusted sources only. This can be done via the WebLogic Server Administration Console or by setting appropriate network channel configurations.
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation8.0 h
- Testing8.0 h
- Review / QA4.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $6,656.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2022-21353 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2022-21353 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data