CVE-2014-4210 is a server-side request forgery vulnerability in the WLS Web Services component of Oracle WebLogic Server, affecting Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0. The UDDI Explorer functionality can be induced to issue requests to attacker-selected network locations, allowing use of the WebLogic host as a request proxy. The vulnerable request handling may also permit CRLF injection to influence the generated outbound request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a highly aggressive, multi-stage exploit targeting Oracle WebLogic servers vulnerable to deserialization flaws (CVE-2014-4210, CVE-2017-10271, and a claimed CVE-2024-666). The main exploit script (exp.py) is written in Python and orchestrates a series of attacks: - It scans the internal network (192.168.0.0/16) for hosts with open ports (7001, 8080, 22, 443) and attempts to exploit them. - The exploit leverages SSRF to access AWS metadata endpoints, stealing cloud credentials and using them to launch malicious EC2 instances. - It delivers a SOAP/XML payload to the WebLogic server to achieve remote code execution, downloading and executing further malware from a hardcoded C2 server (94.666.13.37). - A ransomware payload is deployed, encrypting files and deleting databases, with a ransom note left on the target. - The script is capable of lateral movement, brute-forcing ports across the internal network, and persistence via cloud resource abuse. The README.md is written in a provocative style, outlining the exploit's destructive capabilities and providing usage instructions. The repository is structured with a single main exploit script (exp.py) and a README. The code is operational, with hardcoded payloads and C2 endpoints, and is not part of a known exploit framework. The exploit is highly destructive and intended for offensive operations against unpatched WebLogic servers and associated cloud infrastructure.
This repository is a Python-based exploit toolkit targeting CVE-2014-4210, an SSRF vulnerability in Oracle WebLogic's UDDI Explorer. The main script, SSRFX.py, provides three primary functions: (1) internal network liveness detection, (2) port scanning of internal hosts, and (3) exploitation of internal Redis servers to achieve remote code execution via a reverse shell. The toolkit leverages SSRF to pivot from the vulnerable WebLogic server to internal network resources. The 'getshell' function crafts a payload that abuses Redis's configuration to write a cron job, which then executes a bash reverse shell to the attacker's host and port. The code is modular, with supporting libraries for command-line parsing, logging, and port-to-service mapping. The exploit requires the attacker to specify the vulnerable WebLogic URL, internal network ranges, and (for getshell) attacker and target host/port information. The repository is operational and provides a working exploit chain for SSRF-based internal network attacks and remote code execution via Redis.
This repository provides a Python 3 exploit script (Weblogic-SSRF.py) targeting the Oracle WebLogic Server SSRF vulnerability (CVE-2014-4210) in the /uddiexplorer/SearchPublicRegistries.jsp endpoint. The script allows an attacker to exploit the SSRF flaw by injecting arbitrary host and port values into the 'operator' parameter, causing the WebLogic server to initiate requests to internal or external systems. The script supports scanning single or multiple targets, custom ports, and various subnet ranges (Class A, B, C, or custom lists), and can detect open services within the internal network from the perspective of the vulnerable WebLogic server. The included JSON file (Weblogic_SSRF.json) documents the vulnerability, provides detection and exploitation steps, and references external resources. The README.md explains usage, command-line options, and provides example scenarios. The exploit is a proof-of-concept for network reconnaissance and vulnerability confirmation, not a weaponized tool.
This repository is a graphical proof-of-concept (PoC) exploit for CVE-2014-4210, an SSRF vulnerability in Oracle WebLogic Server's UDDI Explorer. The exploit is implemented as a Qt-based C++ application with a GUI. The user provides the URL of a vulnerable WebLogic UDDI Explorer endpoint and a target host. The tool then iterates over TCP ports (1-65535 by default), crafting requests that abuse the SSRF flaw to check if each port is open from the perspective of the WebLogic server. The main logic is in 'src/mainwindow.cpp', where the application constructs the SSRF payload and processes the results. The repository includes UI resources, a custom style sheet, and a legal disclaimer. No weaponized or automated post-exploitation payloads are present; the tool is strictly a port scanner leveraging SSRF. The exploit is a standalone PoC and not part of a larger framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.