CVE-2024-21006 is an easily exploitable vulnerability in the Core component of Oracle WebLogic Server affecting supported versions 12.2.1.4.0 and 14.1.1.0.0. An unauthenticated attacker with network access to the server over the T3 or IIOP protocols can exploit the issue. Successful exploitation compromises the confidentiality of data accessible to the targeted Oracle WebLogic Server instance. Publicly available information identifies the affected component, attack vector, affected versions, and resulting confidentiality impact, but does not provide sufficient technical detail to identify the specific vulnerable function or code path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (POC) exploit for CVE-2024-21006, a JNDI injection vulnerability in Oracle WebLogic Server. The main code is in 'src/org/example/messageDestinationReference.java', which, when executed, connects to a target WebLogic server via IIOP and attempts to bind and look up a MessageDestinationReference object that references an attacker-controlled LDAP URL. This can trigger a JNDI lookup on the target, potentially leading to remote code execution if the LDAP server serves a malicious payload. The exploit is run as a Java application, taking the target IP, port, and LDAP URL as arguments. The repository is structured with a README for usage instructions, a MANIFEST file specifying the main class, and the Java source code implementing the exploit logic. No hardcoded endpoints are present; all are supplied at runtime, making the exploit flexible for targeting different servers and LDAP payloads.
This repository contains a Java-based proof-of-concept exploit for CVE-2024-21006, targeting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 running on JDK <= 1.8.191. The main code is in 'weblogic/src/com/example/test/Test.java', which provides a GUI for the user to input a target WebLogic server URL and an attacker-controlled LDAP URL. When the 'attack' button is pressed, the exploit parses the target's IP and port, then uses WebLogic's JNDI functionality to trigger a lookup to the specified LDAP server. The LDAP server (e.g., JNDIExploit) must be set up separately and is expected to deliver the actual malicious payload. The exploit demonstrates the vulnerability but does not include a weaponized payload itself. The repository structure is simple, with a single Java exploit file, a manifest, and project configuration files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.