Record summary

CVE-2021-2135 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 7, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List12.2.1.3.0affected
12.2.1.4.0affected
14.1.1.0.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALOracle WebLogic Server - Remote Code ExecutionCVSS 9.8

Oracle WebLogic Server (12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0) contains a remote code execution caused by unauthenticated access via T3, IIOP, letting attackers take over the server, exploit requires network access.

Impact

Attackers can fully compromise the server, leading to data breach, service disruption, and potential further exploitation.

Remediation

Update to the latest patched version of Oracle WebLogic Server.

WeaknessesCWE-502
Authorshnd3884
Template tagscvecve2021weblogicoraclercevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:oracle:weblogic_server"
Shodan: product:"WebLogic"
Shodan: http.server:"WebLogic"
Shodan: port:7001
FOFA: product="WebLogic" || header="WebLogic Server"

Source: ProjectDiscovery

References

2