ZeroHour

CVE-2023-21839

KEV PoC large

Unauthenticated Remote Code Execution in Oracle WebLogic Server via T3/IIOP

CISA: Oracle WebLogic Server Unspecified Vulnerability

CVSS 3.1
7.5 high
EPSS
100%p100
Published
()
KEV added
AI analysis

Oracle WebLogic Server contains a vulnerability that allows an unauthenticated attacker with network access to the server's T3 or IIOP endpoints to fully compromise the WebLogic instance (widely characterized as remote code execution). It is triggered simply by sending crafted T3 or IIOP protocol requests to a listening WebLogic server, requiring no credentials or user interaction. An attacker who succeeds gains the ability to run code on the application server host, providing a foothold in the application tier that can be used for lateral movement; CISA notes that ransomware use is currently unknown. Any organization running affected Oracle WebLogic Server versions is exposed, particularly where the T3/IIOP listeners are reachable from the internet or from less-trusted network zones. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-05-01, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile).

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2023-21839 (January 2023 CPU) to WebLogic Server per Oracle's instructions, prioritizing internet-facing systems given the KEV listing. Restrict network access to the T3 (default TCP 7001) and IIOP listeners to trusted hosts only, and check exposed servers for signs of compromise. Ransomware linkage is unknown, so treat all affected instances as patch-priority rather than only ransomware-targeted ones.

Affected
Oracle WebLogic Server
Estimated exposure
largetens of thousands (≈10,000–40,000) of internet-exposed WebLogic servers, with a far larger internal installed base — Public internet scan datasets (Shodan/FOFA-style scans of WebLogic T3/IIOP listeners, typically TCP 7001) have consistently shown on the order of tens of thousands of exposed instances, and WebLogic's role as core enterprise middleware…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CISA Known Exploited Vulnerability
Affected
Oracle WebLogic Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
weblogic server
Weakness
CWE-502, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news