CVE-2014-4210
published 2014-07-17CVE-2014-4210: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect…
PriorityP345medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
38.15%
98.4th percentile
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/uddiexplorer/SearchPublicRegistries.jsp?rdoSearch=name&txtSearchname=sdf&txtSearchkey=&txtSearchfor=&selfor=Business+location&btnSubmit=Search&operator=http://{{interactsh-url}}↗
- →Monitor for unauthenticated GET requests to /uddiexplorer/SearchPublicRegistries.jsp with an attacker-controlled 'operator' parameter, which is the SSRF injection point for CVE-2014-4210. ↗
- →Detect exploitation attempts by inspecting the HTTP response body for the string 'Search public registries' combined with an out-of-band HTTP callback (OAST/interactsh), confirming the SSRF triggered an outbound connection. ↗
- →Use Shodan/FOFA queries to identify exposed Oracle WebLogic servers as potential targets: search for title 'Weblogic', http.title 'weblogic', or http.html 'weblogic application server'. ↗
- →GreyNoise tagged active scanning/exploitation attempts for this CVE as 'Oracle WebLogic CVE-2014-4210 SSRF Attempt' starting November 2023, indicating ongoing mass exploitation activity nearly a decade after disclosure. ↗
- →The SSRF allows probing arbitrary internal TCP ports; responses are verbose enough to infer whether a service is listening, enabling internal network port scanning via the 'operator' parameter. ↗
- ·Vulnerability affects only Oracle Fusion Middleware versions 10.0.2.0 and 10.3.6.0; detection rules should be scoped to these versions to reduce false positives. ↗
- ·The SSRF is exploitable without authentication; no session cookie or credential is required, meaning perimeter controls alone are insufficient if the UDDI endpoint is reachable. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Oracle Weblogic - Server-Side Request Forgery
nuclei·CVSS 5.0
CVE-2014-4210 [MEDIUM] Oracle Weblogic - Server-Side Request Forgery
Oracle Weblogic - Server-Side Request Forgery
An unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
Template:
id: CVE-2014-4210
info:
name: Oracle Weblogic - Server-Side Request Forgery
author: princechaddha
severity: medium
description: An unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
impact: |
Successful exploitation of this vulnerability could allow an attacker to bypass network restrictions and access internal resources.
remediation: |
Apply the latest patches and up
HackerOne
WebLogic Server Side Request Forgery
hackerone·2019-12-02
[MEDIUM] WebLogic Server Side Request Forgery
WebLogic Server Side Request Forgery
Universal Description Discovery and Integration (UDDI) application is publicly available on this WebLogic server. The SearchPublicRegistries.jsp page can be abused by unauthenticated attackers to cause the WebLogic web server to connect to an arbitrary TCP port of an arbitrary host. Responses returned are fairly verbose and can be used to infer whether a service is listening on the port specified. This vulnerability affects Oracle Fusion Middleware 10.0.2, 10.3.6.
The impact of this vulnerability
An attacker can force the WebLogic web server to connect to an arbitrary TCP port of an arbitrary host.
How to fix this vulnerability
Apply the Oracle Critical Patch Update Advisory from July 2014 or restrict access to the UDDI application.
https://blog.gds
Tenable
Identifying Server Side Request Forgery: How Tenable.io Web Application Scanning Can Help
blogs_tenable·2021-11-18
Identifying Server Side Request Forgery: How Tenable.io Web Application Scanning Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://seclists.org/fulldisclosure/2014/Dec/23http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68629http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/94554http://seclists.org/fulldisclosure/2014/Dec/23http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68629http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/94554
2014-07-17
Published