CISA Flags Two Year Old Oracle Flaw
CISA added an old Oracle WebLogic bug to its known exploited list. Federal agencies now must patch or face deadlines.
CVE-2024-21216 scores CVSS 9.8. Attackers reach it over the network with no authentication and can execute code as the server process. The flaw was fixed in October 2024.
It affects WebLogic Server 12.2.1.4 and 14.1.1.0 on multiple platforms. Any exposed admin console or T3 port draws attention from real attackers.
CISA first listed it on the KEV catalog in May 2025.
