ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

highExploit / PoC exploited in the wildimportance 60CVE-2017-3506CVE-2023-21839

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-3506
Unauthenticated OS Command Injection in Oracle WebLogic Server

CVE-2017-3506 is an unauthenticated operating system command injection flaw (CWE-78) in the Web Services subcomponent of Oracle WebLogic Server. A remote attacker with network access over HTTP can trigger it, though the flaw is rated difficult to exploit (high attack complexity). Successful exploitation allows the attacker to create, delete, or modify critical data and gain unauthorized access to critical data — potentially all data accessible to WebLogic Server — without authentication, with no availability impact. Organizations running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, or 12.2.1.2 are exposed, especially where the HTTP interface is internet-reachable. The flaw is under active attack: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-03, EPSS is at 96.3%, and the 8220 gang is exploiting it to deliver infostealers and cryptocurrency miners.

Do: Apply the Oracle Critical Patch Update from April 2017 or later (or upgrade WebLogic Server to a patched, supported release), consistent with CISA's KEV required action to apply vendor mitigations or discontinue use. Until patched, restrict network access to the Web Services HTTP interface. Hunt affected servers for 8220 gang activity — unexpected child processes, cryptomining loads, and infostealer artifacts — since exploitation requires no authentication.

7.496% KEV
  • Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, 12.2.1.2
largetens of thousands (≈10k–100k) of internet-exposed WebLogic servers; substantially more when internal enterprise deployments are counted
CVE-2023-21839
Unauthenticated Remote Code Execution in Oracle WebLogic Server via T3/IIOP

Oracle WebLogic Server contains a vulnerability that allows an unauthenticated attacker with network access to the server's T3 or IIOP endpoints to fully compromise the WebLogic instance (widely characterized as remote code execution). It is triggered simply by sending crafted T3 or IIOP protocol requests to a listening WebLogic server, requiring no credentials or user interaction. An attacker who succeeds gains the ability to run code on the application server host, providing a foothold in the application tier that can be used for lateral movement; CISA notes that ransomware use is currently unknown. Any organization running affected Oracle WebLogic Server versions is exposed, particularly where the T3/IIOP listeners are reachable from the internet or from less-trusted network zones. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-05-01, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile).

Do: Apply the Oracle Critical Patch Update that fixes CVE-2023-21839 (January 2023 CPU) to WebLogic Server per Oracle's instructions, prioritizing internet-facing systems given the KEV listing. Restrict network access to the T3 (default TCP 7001) and IIOP listeners to trusted hosts only, and check exposed servers for signs of compromise. Ransomware linkage is unknown, so treat all affected instances as patch-priority rather than only ransomware-targeted ones.

7.5100% KEV PoC
  • Oracle WebLogic Server
largetens of thousands (≈10,000–40,000) of internet-exposed WebLogic servers, with a far larger internal installed base
Full article303 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 04, 2024Network Security / Cryptocurrency

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting the Oracle WebLogic Server to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Tracked as CVE-2017-3506 (CVSS score: 7.4), the issue concerns an operating system (OS) command injection vulnerability that could be exploited to obtain unauthorized access to susceptible servers and take complete control.

"Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document," CISA said.

While the agency did not disclose the nature of attacks exploiting the vulnerability, the China-based cryptojacking group known as the 8220 Gang (aka Water Sigbin) has a history of leveraging it since early last year to co-opt unpatched devices into a crypto-mining botnet.

According to a recent report published by Trend Micro, the 8220 Gang has been observed weaponizing flaws in the Oracle WebLogic server (CVE-2017-3506 and CVE-2023-21839) to launch a cryptocurrency miner filelessly in memory by means of a shell or PowerShell script depending on the operating system targeted.

"The gang employed obfuscation techniques, such as hexadecimal encoding of URLs and using HTTP over port 443, allowing for stealthy payload delivery," security researcher Sunil Bharti said. "The PowerShell script and the resulting batch file involved complex encoding, using environment variables to hide malicious code within seemingly benign script components."

In light of the active exploitation of CVE-2017-3506, federal agencies are recommended to apply the latest fixes by June 24, 2024, to protect their networks against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/06/oracle-weblogic-server-os-command.html