CVE-2023-21839
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 17, 2022
- Published Date
- January 17, 2023
- Last Updated
- February 13, 2025
- Vendor
- Oracle Corporation
- Product
- WebLogic Server
- Description
- Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- partial
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-05-01 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/iiop/cve_2023_21839_weblogic_rce.rb | 2025-04-29 11:01:25 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cve_2023_21839_weblogic_rce
Type: metasploit • Created: Unknown
houqe/POC_CVE-2023-21839
Type: github • Created: 2023-04-15 08:57:10 UTC • Stars: 15
Firebasky/CVE-2023-21839
Type: github • Created: 2023-03-11 08:26:30 UTC • Stars: 27
ASkyeye/CVE-2023-21839
Type: github • Created: 2023-02-24 13:54:42 UTC • Stars: 86
DXask88MA/Weblogic-CVE-2023-21839
Type: github • Created: 2023-02-21 16:08:56 UTC • Stars: 234