Improper input validation in Oracle WebLogic Server - CVE-2021-2109
Published: January 20, 2021 / Updated: September 1, 2022
Vulnerability identifier: #VU49793
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-2109
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Console component in Oracle WebLogic Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle WebLogic Server
How to mitigate CVE-2021-2109
Install updates from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #8322 - oracle-weblogic-CVE-2021-2109 (Oracle Weblogic RCE - CVE-2022-2109) (September 1, 2022)
- Exploit #6610 - CVE-2021-2109 (CVE-2021-2109 basic scanner) (August 9, 2021)
- Exploit #6457 - CVE-2021-2109 () (June 20, 2021)
- Exploit #5432 - CVE-2021-2109_poc (weblogic CVE-2021-2109批量验证poc) (May 18, 2021)
- Exploit #5418 - CVE-2021-2109 (CVE-2021-2109 && Weblogic Server RCE via JNDI) (May 18, 2021)
- Exploit #5227 - PocList (Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongy (March 18, 2021)
- Exploit #5076 - Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated) (January 25, 2021)