CISA flags two-year-old Oracle flaw as actively exploited in attacks
CISA has identified a two-year-old Oracle WebLogic Server vulnerability (CVE-2024-21182) as actively being exploited in attacks, prompting a directive for federal agencies to immediately patch their systems. The vulnerability allows unauthorized access to sensitive data and represents a significant risk due to its ease of exploitation. This incident highlights the ongoing importance of timely patching and proactive security measures against known vulnerabilities.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) 22-01, mandating that federal agencies patch their Oracle WebLogic Server systems against CVE-2024-21182. This vulnerability, discovered in July 2024, allows unauthenticated attackers with network access via T3 or IIOP to compromise the server, potentially gaining access to critical data or complete control. The vulnerability affects versions 12.2.1.4.0 and 14.1.1.0.0, and Shodan currently identifies over 1,592 vulnerable servers exposed online. CISA’s action underscores the persistent threat posed by unpatched software and the need for rapid response to emerging exploits.