CVE-2021-2394 is an easily exploitable vulnerability in Oracle WebLogic Server (Oracle Fusion Middleware, component: Core) affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The issue is reachable by an unauthenticated attacker with network access over T3 and/or IIOP, and successful exploitation can result in compromise/takeover of the Oracle WebLogic Server instance. The referenced CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (base score 9.8).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (POC) exploit for CVE-2021-2394, a critical deserialization vulnerability in Oracle WebLogic Server. The main exploit file, CVE_2021_2394.java, constructs a malicious Java object graph that leverages JNDI and IIOP to trigger a deserialization attack on a vulnerable WebLogic instance. The exploit requires three arguments: the target host, target port, and an attacker-controlled LDAP URL. The exploit connects to the target WebLogic server using IIOP, binds a crafted object that references the LDAP server, and attempts to trigger remote code execution via deserialization. The Reflections.java file provides utility methods for manipulating Java reflection and object instantiation, supporting the exploit's payload construction. The README.md explains usage, prerequisites (including JDK version restrictions and the need for an LDAP server), and references for further reading. The repository is structured as a standalone Java POC, not part of a larger framework, and is intended for security research and testing on vulnerable WebLogic installations.
This repository is a proof-of-concept (POC) exploit for CVE-2021-2394, a critical deserialization vulnerability in Oracle WebLogic Server. The main file, CVE_2021_2394.java, constructs a malicious Java object graph using various gadget classes and binds it to the target WebLogic server's JNDI registry via the IIOP protocol. The exploit requires the attacker to provide the target's IP, port, and an attacker-controlled LDAP URL, which is used to facilitate the JNDI attack. The exploit leverages Java's serialization and reflection mechanisms to craft the payload and bypass certain security restrictions. The Reflections.java file provides utility methods for manipulating Java reflection and object instantiation, supporting the main exploit logic. The README.md provides usage instructions, prerequisites (such as running an LDAP server and using a vulnerable WebLogic/JDK version), and references for further reading. The exploit is network-based, targeting WebLogic servers accessible over IIOP, and aims to achieve remote code execution by exploiting unsafe deserialization through JNDI lookups.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.