CVE-2023-21839
Oracle WebLogic Server Unspecified Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 May 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 99.90% probability · 100th percentile
- CISA KEV
- Listed 1 May 2023 · due 22 May 2023
- Weakness
- CWE-502, CWE-306
- Affected
- oracle/weblogic server
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://www.oracle.com/security-alerts/cpujan2023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-21839
References
- http://packetstormsecurity.com/files/172882/Oracle-Weblogic-PreAuth-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpujan2023.htmlPatch, Vendor Advisory
- http://packetstormsecurity.com/files/172882/Oracle-Weblogic-PreAuth-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpujan2023.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21839US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.