| Title | Oracle WebLogic Server - Remote Code Execution |
|---|---|
| Author | hnd3884 |
| Severity | Critical |
| Impact | Attackers can fully compromise the server, leading to data breach, service disruption, and potential further exploitation. |
| Remediation | Update to the latest patched version of Oracle WebLogic Server. |
| CVSS Score | 9.8 |
| EPSS Score | 0.71821 |
| CVE ID | CVE-2021-2135 |
| CWE ID | CWE-502 |
| Shodan Query | cpe:"cpe:2.3:a:oracle:weblogic_server"product:"WebLogic"http.server:"WebLogic"port:7001 |
| Fofa Query | product="WebLogic" || header="WebLogic Server" |
| Tags | cve cve2021 weblogic oracle rce vkev |
Oracle WebLogic Server (12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0) contains a remote code execution caused by unauthenticated access via T3, IIOP, letting attackers take over the server, exploit requires network access.
No request captured.
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-2135.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-2135.pcap
N/AN/A