CVE-2021-2135
Oracle Fusion Middleware WebLogic Server Coherence Container Security Bypass
Record summary
CVE-2021-2135 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 7, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WebLogic ServerBrowse Oracle / WebLogic Server | VulnCheck | Version data not supplied | |
WebLogic ServerBrowse Oracle Corporation / WebLogic Server | CVE List | 12.2.1.3.0 | affected |
| 12.2.1.4.0 | affected | ||
| 14.1.1.0.0 | affected | ||
Nuclei templates
1ProjectDiscoveryCRITICALOracle WebLogic Server - Remote Code ExecutionCVSS 9.8
Oracle WebLogic Server (12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0) contains a remote code execution caused by unauthenticated access via T3, IIOP, letting attackers take over the server, exploit requires network access.
Impact
Attackers can fully compromise the server, leading to data breach, service disruption, and potential further exploitation.
Remediation
Update to the latest patched version of Oracle WebLogic Server.
Source: ProjectDiscovery