Junglewise Threat Intelligence

CVE-2023-21839: Oracle WebLogic Server Unspecified Vulnerability

CVE-2023-21839 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-05-01

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains a vulnerability in its Core component that allows unauthenticated attackers with network access via T3 or IIOP protocols to compromise the system. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible by the server.

Affected products

  • Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2023-01-17: disclosed: NVD Published Date
  • 2023-01-17: patched: Oracle Critical Patch Update (CPU) January 2023
  • 2023-05-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-01: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats