Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026)
Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogic Server itself. Users should immediately apply the provided patches to mitigate the risks.
Oracle has announced multiple vulnerabilities within its WebLogic Server platform. These vulnerabilities allow an attacker to potentially compromise data confidentiality and integrity. The affected products include various versions of the WebLogic Server Proxy Plug-in, specifically versions 12.2.1.4.0, 14.1.2.0.0, 15.1.1.0.0, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0, and the WebLogic Server itself (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The vulnerabilities are detailed through a series of CVE identifiers, including CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, CVE-2026-34481, CVE-2026-5598, CVE-2026-60153, CVE-2026-60196, CVE-2026-60198, CVE-2026-60199, CVE-2026-60200, CVE-2026-60201, CVE-2026-60202, CVE-2026-60203, CVE-2026-60204, CVE-2026-60205, CVE-2026-60206, CVE-2026-60207, CVE-2026-60208, CVE-2026-60291, CVE-2026-60292, CVE-2026-60293, CVE-2026-60294, CVE-2026-60312, CVE-2026-60313, CVE-2026-60343, CVE-2026-60364, CVE-2026-60365, and CVE-2026-60527, CVE-2026-60528, CVE-2026-60529. The CERT-FR bulletin provides further details and links to the official Oracle security alerts.