CVE-2016-3505: Oracle WebLogic Server

High severity, CVSS 8.8. EPSS: 5.7% chance of exploitation in the next 30 days.

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to JavaServer Faces.

Affected products

  • Oracle WebLogic Server: version 10.3.6.0.0 only; version 12.1.3.0.0 only; version 12.2.1.0.0 only

Published 2016-10-25. Last modified 2026-06-17.