CVE-2023-21839 is an insecure deserialization vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects WebLogic Server versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. An unauthenticated remote attacker can reach the vulnerable functionality through the T3 or IIOP protocols. Oracle assigned CVSS v3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a self-contained lab exploit for Oracle WebLogic Server CVE-2024-21182, described as an unauthenticated T3/IIOP JNDI injection leading to server-side LDAP lookup and, in the provided lab conditions, remote code execution. The repo is not tied to a common exploit framework; it contains custom Java, Python, Bash, and Docker components. Structure and purpose: - poc/CVE_2024_21182.java is the main exploit client. It connects to a WebLogic T3 endpoint, constructs a malicious weblogic.application.naming.MessageDestinationReference, reflectively inserts it into an AggregatableOpaqueReference, binds it into JNDI, and triggers lookup() so the server performs an attacker-controlled LDAP lookup. - exploit/ldap_server.py is the attacker infrastructure. It implements a minimal LDAP server that answers searches with a javaNamingReference containing javaClassName=Exploit, javaFactory=Exploit, and javaCodeBase pointing to an HTTP server. The same script also starts an HTTP server to host the compiled class file. - exploit/Exploit.java is the payload class. Its static initializer executes /bin/sh -c 'id ...; uname -a ...' and writes output to /tmp/RCE_PROOF_CVE_2024_21182 on the victim. - exploit/build.sh recompiles Exploit.java to Java 8 bytecode for compatibility with the lab’s older JDK. - docker-compose.yml provisions a vulnerable WebLogic container and an attacker container exposing the LDAP/HTTP services. - validate.sh automates end-to-end reproduction: waits for WebLogic readiness, copies and compiles the PoC inside the container against the live WebLogic classpath, runs the exploit against 127.0.0.1:7001 with ldap://attacker:1389/Evil, and checks for the proof file. Main exploit capability: The exploit provides unauthenticated network-triggered JNDI injection over T3, causing the target WebLogic server to initiate outbound LDAP and HTTP connections to attacker-controlled infrastructure. In the included lab, this results in arbitrary command execution via remote Java class loading. On newer JDKs or patched systems, the same technique may degrade to SSRF/outbound lookup without RCE. Notable targeting details: The README states Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 are the CVE-listed affected versions, while the lab uses vulhub/weblogic:12.2.1.3-2018 to reproduce the vulnerable class behavior. The exploit specifically abuses WebLogic classes AggregatableOpaqueReference and MessageDestinationReference to bypass prior protections associated with CVE-2023-21839. Overall, this is a real operational lab exploit with a working payload and attacker infrastructure, not merely a detector or README-only proof of concept.
This repository contains a single Metasploit module implementing a weaponized exploit for CVE-2023-21839, a critical unauthenticated remote code execution vulnerability in Oracle WebLogic Server (versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 prior to the January 2023 patch). The exploit leverages a deserialization flaw in the ForeignOpaqueReference class via the IIOP (CORBA) protocol, allowing an attacker to trigger a JNDI injection and force the target to load a malicious Java class from an attacker-controlled HTTP server (via an LDAP redirect). The module is highly automated and integrated into the Metasploit framework, supporting payload selection (defaulting to a bash reverse shell) and providing full unauthenticated RCE as the 'oracle' user. The attacker must control both LDAP and HTTP servers to deliver the payload. The code is well-documented, references multiple technical writeups, and is operationally mature.
This repository contains a Python proof-of-concept exploit for CVE-2023-21839, a vulnerability in Oracle WebLogic Server (versions 12 and 14). The main file, CVE-2023-21839.py, implements a class that connects to a target WebLogic server over the T3 protocol (typically on TCP port 7001) and performs a series of crafted protocol operations. The script dynamically extracts protocol keys from the server's response and constructs further requests to demonstrate the vulnerability. The exploit requires the attacker to specify the target's IP, port, and an LDAP URL, which is used in the protocol payloads. The script does not provide remote code execution or a shell, but serves as a POC to verify the presence of the vulnerability and the ability to manipulate the protocol. The repository also includes a README.md with usage instructions and a disclaimer. No hardcoded endpoints are present; all targets are user-supplied at runtime.
This repository is a Go-based exploit for CVE-2023-21839, a remote code execution vulnerability in Oracle WebLogic Server (versions 12 and 14). The exploit is fully implemented in Go and does not require any Java dependencies. It constructs and sends raw GIOP/IIOP protocol messages over TCP to the target WebLogic server, exploiting the server's JNDI lookup mechanism to trigger a connection to an attacker-controlled LDAP server. The attacker must provide a malicious LDAP server (e.g., using marshalsec or similar tools) to deliver a serialized Java payload for RCE. The main entry point is 'cmd/main.go', which handles argument parsing, protocol message construction, and network communication. The codebase is modular, with separate files for protocol constants, message structures, and serialization logic. The exploit is operational and has been tested on multiple platforms and WebLogic versions, as described in the README. No hardcoded IPs or domains are present; all endpoints are user-supplied at runtime.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-21839, a JNDI injection vulnerability in Oracle WebLogic Server (versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0). The main exploit is implemented in Java (CVE_2023_21839.java) and is designed to be run as a standalone JAR. The exploit takes two arguments: the target WebLogic server's IP:port and an attacker-controlled LDAP URL. It establishes a JNDI context to the target using the T3 protocol, then binds a malicious ForeignOpaqueReference object with a remote JNDI name pointing to the LDAP server. This can trigger a JNDI lookup on the target, potentially leading to remote code execution if the LDAP server serves a malicious payload. The README provides usage instructions and references a popular JNDI exploit tool for setting up the LDAP server. The repository is structured with a single Java exploit file, a manifest for JAR packaging, and a README. No hardcoded IPs or domains are present; endpoints are provided as runtime arguments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical Oracle WebLogic T3/IIOP deserialization flaw cited as precedent for exploitation of this attack surface.
An easily exploitable, unauthenticated network-accessible Oracle WebLogic Server (Core) flaw reachable over T3/IIOP that can allow compromise and unauthorized access to data; the provided nuclei template demonstrates exploitation by triggering an out-of-band (Interactsh/OAST) DNS callback via an injected LDAP URL.
An insecure deserialization vulnerability in Oracle WebLogic Server that allows remote attackers to execute arbitrary code via crafted requests, enabling full compromise of the server.
An Oracle WebLogic Server insecure deserialization vulnerability exploited by Water Sigbin to deploy a cryptocurrency miner via PowerShell.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.