🔙 목록으로 돌아가기

CVE-2021-2135: Oracle WebLogic Server - Remote Code Execution

TitleOracle WebLogic Server - Remote Code Execution
Authorhnd3884
SeverityCritical
ImpactAttackers can fully compromise the server, leading to data breach, service disruption, and potential further exploitation.
RemediationUpdate to the latest patched version of Oracle WebLogic Server.
CVSS Score9.8
EPSS Score0.71821
CVE IDCVE-2021-2135
CWE IDCWE-502
Shodan Querycpe:"cpe:2.3:a:oracle:weblogic_server"product:"WebLogic"http.server:"WebLogic"port:7001
Fofa Queryproduct="WebLogic" || header="WebLogic Server"
Tags cve cve2021 weblogic oracle rce vkev

🔍 Vulnerability Description

Oracle WebLogic Server (12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0) contains a remote code execution caused by unauthenticated access via T3, IIOP, letting attackers take over the server, exploit requires network access.

🌐 HTTP Request

No request captured.

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-2135.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-2135.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A