CVE-2010-2375 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 6.5% (pctl 94)
Patch early
A public exploit exists.
Description
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| EPSS | 6.51% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-07-13 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| bea | weblogic server |
| bea systems | weblogic server |
| oracle | weblogic server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle WebLogic Server 10.3.3 - Encoded URL | 2010-07-13 |
References
→ the Explorer · watch your stack · NVD