Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 2.62 KB

CVE-2023-21979.md

File metadata and controls

12 lines (10 loc) · 2.62 KB

Weblogic ForeignOpaqueReference Remote Code Execution Vulnerability (CVE-2023-21979)

Vulnerability Weblogic ForeignOpaqueReference Remote Code Execution Vulnerability (CVE-2023-21979)
Chinese name Weblogic ForeignOpaqueReference 反序列化远程代码执行漏洞(CVE-2023-21979)
CVSS core 7.5
FOFA Query (click to view the results directly) (body="Welcome to WebLogic Server") || (title=="Error 404--Not Found") || (((body="<h1>BEA WebLogic Server" || server="Weblogic" || body="content="WebLogic Server" || body="<h1>Welcome to Weblogic Application" || body="<h1>BEA WebLogic Server") && header!="couchdb" && header!="boa" && header!="RouterOS" && header!="X-Generator: Drupal") || (banner="Weblogic" && banner!="couchdb" && banner!="drupal" && banner!=" Apache,Tomcat,Jboss" && banner!="ReeCam IP Camera" && banner!="<h2>Blog Comments")) || (port="7001" && protocol=="weblogic")
Number of assets affected 126908
Description WebLogic Server is one of the application server components applicable to cloud and traditional environments. WebLogic has a remote code execution vulnerability, which allows an unauthenticated attacker to access and destroy the vulnerable WebLogic Server through the IIOP protocol network. A successful exploitation of the vulnerability can cause the WebLogic Server to be taken over by the attacker, resulting in remote code execution.
Impact WebLogic has a remote code execution vulnerability, which allows an unauthenticated attacker to access and destroy the vulnerable WebLogic Server through the IIOP protocol network. A successful exploitation of the vulnerability can cause the WebLogic Server to be taken over by the attacker, resulting in remote code execution.