Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily
Low-priv SAML abuse with scope change on WebLogic Core — the historical bullseye of the CISA KEV catalog. Patch, don't wait.