
Oracle Fusion Middleware Oracle HTTP Server / WebLogic Server Proxy Plug-in has an easily exploitable, unauthenticated, network-reachable flaw allowing compromise over HTTP. Affected supported versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0.
Oracle Fusion Middleware Oracle HTTP Server / WebLogic Server Proxy Plug-in has an easily exploitable, unauthenticated, network-reachable flaw allowing compromise over HTTP. Affected supported versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0.
CVSS 10.0 (per Oracle / NVD text) and remotely reachable over HTTP.
The check.py is used only for exposure checking and banner/version hinting only. First run requirements.txt -> check.py
For testing and research purposes, I have also included exploit.py it is meant to;
Example output from exploit.py:
[ATTACKER PERSPECTIVE] - Theoretical Kill Chain
check.py or similar to confirm version in AFFECTED_TRAINS.ProxyServlet.wl-proxy-client-ip header with ;Base64 payload.[DEFENDER PERSPECTIVE] - IMMEDIATE ACTIONS (BEYOND PATCHING)[citation:6][citation:8] *** PATCHING IS NON-NEGOTIABLE. APPLY ORACLE'S JANUARY 2026 CPU[citation:10]. ***
TARGET_DISCOVERY:
check.py or a variant to fingerprint for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)[citation:1][citation:7].VULNERABILITY_CONFIRMATION:
X-WebLogic-KeepAlive headers and observe the response. A crash, hang, or specific error message is a positive indicator[citation:6].EXPLOIT_DEVELOPMENT & TESTING (The Dark Art):
DEPLOYMENT: