CVE-2022-21371

WebLogic Local File Inclusion: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published January 19, 2022 · Updated June 30, 2026

Mitigated by Waratek HIGH CVSS 7.5 v3.1

The vulnerability

Information disclosure via HTTP path traversal

A crafted HTTP request lets an unauthenticated attacker traverse outside the intended web root and read arbitrary files accessible to the WebLogic Server process. There is no authentication requirement and the flaw is easily exploitable over the network, giving attackers a low-effort path to config files, credentials, and other sensitive data on the server.

Affected softwareOracle WebLogic Server
Affected versions12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
WeaknessPath traversal (local file inclusion) (CWE-22)
Published2022-01-19
SeverityHIGH · CVSS 7.5

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

WebLogic Local File Inclusion FAQ

Is WebLogic Local File Inclusion (CVE-2022-21371) exploitable?

CVE-2022-21371 carries a CVSS 7.5/10 (HIGH) rating and affects Oracle WebLogic Server 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0. A crafted HTTP request lets an unauthenticated attacker traverse outside the intended web root and read arbitrary files accessible to the WebLogic Server process. There is no authentication requirement and the flaw is easily exploitable over the network, giving attackers a low-effort path to config files, credentials, and other sensitive data on the server.

How does Waratek mitigate WebLogic Local File Inclusion (CVE-2022-21371)?

Waratek RASP blocks exploitation of WebLogic Local File Inclusion (CVE-2022-21371) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was WebLogic Local File Inclusion (CVE-2022-21371) exploited after disclosure?

A working exploit for CVE-2022-21371 appeared within 7 days of its NVD disclosure, on January 25, 2022.

Protect your apps in production

Get protected against WebLogic Local File Inclusion - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2022-21371 and attacks like it, and get you covered in production.