PT-2023-9842 · Oracle · Oracle Weblogic Server
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle WebLogic Server version 12.2.1.4.0
Oracle WebLogic Server version 14.1.1.0.0
Description
A flaw in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware, is caused by insufficient input validation and a post-deserialization issue. This allows an unauthenticated remote attacker with network access to compromise the server via T3 or IIOP protocols. Successful exploitation can lead to unauthorized access to critical data, complete access to all accessible server data, or remote code execution. There is evidence of active exploitation in the wild, with threat actors targeting internet-exposed servers to deploy ransomware, steal data, or install crypto-miners.
Recommendations
Apply the July 2024 Critical Patch Update for version 12.2.1.4.0.
Apply the July 2024 Critical Patch Update for version 14.1.1.0.0.
As a temporary mitigation, block external access to T3 and IIOP protocols (default port 7001) and restrict exposure to trusted networks only.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Weblogic Server