CVE-2021-2109 is a vulnerability in the Console component of Oracle WebLogic Server, affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The flaw allows a high-privileged attacker with network access via HTTP to fully compromise the affected server. The vulnerability is easily exploitable and can result in a complete takeover of the Oracle WebLogic Server instance, impacting confidentiality, integrity, and availability. Public exploit code is available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository provides a proof-of-concept exploit for CVE-2021-2109, a remote code execution vulnerability in Oracle WebLogic Server's Console component. The exploit targets authenticated users with network access and leverages a JNDI injection via the WebLogic console to trigger deserialization of a malicious Java class (Exploit.java). The repository contains four files: a Java exploit source file (Exploit.java), a large JAR file (marshalsec-0.0.3-SNAPSHOT-all.jar) used to run a malicious LDAP server, a .gitattributes file, and a detailed README.md. The README provides step-by-step instructions, including setting up the LDAP server, compiling the exploit, and crafting the HTTP request to trigger the vulnerability. The main payload is a Java class that executes arbitrary system commands (demonstrated with 'calc'). Several network endpoints are fingerprintable, including the LDAP and HTTP URLs used in the attack chain. The exploit demonstrates the vulnerability but does not provide a weaponized or automated attack tool.
This repository contains a proof-of-concept exploit for Oracle WebLogic Server targeting CVE-2021-2109, a remote code execution vulnerability via JNDI injection. The repository consists of a README and a 'payload' file. The payload is a raw HTTP POST request crafted to exploit the vulnerability by sending a request to the /console/css/%252e%252e%252f/consolejndi.portal endpoint, with a JNDI reference to a remote LDAP server. The exploit demonstrates how an attacker can execute arbitrary commands (e.g., 'ls') on the target server. The repository is minimal and does not include automation scripts, but provides a clear example of the exploit request structure. No hardcoded IPs or credentials are present; the payload uses placeholders for the target and LDAP server addresses.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.