CVE-2022-21371
published 2022-01-19CVE-2022-21371: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are…
PriorityP188high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
92.33%
99.8th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →HTTP GET requests using the './/WEB-INF/' or './/META-INF/' path traversal prefix pattern are characteristic of CVE-2022-21371 exploitation attempts against Oracle WebLogic Server. ↗
- →Successful exploitation returns XML content; detect responses with Content-Type 'text/xml' or 'application/xml' to requests containing the './/WEB-INF/' path prefix. ↗
- →Shodan/FOFA queries can identify exposed Oracle WebLogic instances as targets: search for HTTP title 'oracle peoplesoft sign-in' or product 'oracle weblogic'. ↗
- →The vulnerability is in the Web Container component; unauthenticated HTTP GET requests with double-slash path traversal (e.g., './/WEB-INF/weblogic.xml') should be blocked or alerted at the WAF/proxy layer. ↗
- ·Affected versions are strictly 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0; detection rules should be scoped to these versions to reduce false positives. ↗
- ·The Nuclei template uses 'unsafe: true' and 'stop-at-first-match: true', meaning automated scanners may only send one of the two payload paths; defenders should monitor for all four known LFI path variants. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Container — CVE-2022-21371
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2022-21371 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Web Container — CVE-2022-21371
Oracle Oracle Fusion Middleware Risk Matrix: Web Container vulnerability
CVE: CVE-2022-21371
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
GHSA
GHSA-6rxv-546p-5g4j: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container)
ghsa_unreviewed·2022-02-10
CVE-2022-21371 [HIGH] CWE-22 GHSA-6rxv-546p-5g4j: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
VulnCheck
Oracle WebLogic Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2022·CVSS 7.5
CVE-2022-21371 [HIGH] Oracle WebLogic Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Oracle WebLogic Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected: Oracle WebLogic Server
Required Action: Apply remediations or mitigations per vendo
No detection rules found.
Exploit-DB
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
exploitdb·2022-01-27·CVSS 7.5
CVE-2022-21371 [HIGH] Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
---
# Exploit Title: Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
# Date: 25/1/2022
# Exploit Author: Jonah Tan (@picar0jsu)
# Vendor Homepage: https://www.oracle.com
# Software Link:
https://www.oracle.com/middleware/technologies/weblogic-server-installers-downloads.html
# Version: 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0
# Tested on: Windows Server 2019
# CVE : CVE-2022-21371
# Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion
Middleware (component: Web Container).
Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
and 14.1.1.0.0.
Easily exploitable vulnerability allows unauthenticated attacker with
network access via HTTP to compromise Oracle WebLogic
Nuclei
Oracle WebLogic Server Local File Inclusion
nuclei·CVSS 7.5
CVE-2022-21371 [HIGH] Oracle WebLogic Server Local File Inclusion
Oracle WebLogic Server Local File Inclusion
An easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Successful attacks of this vulnerability can result in unauthorized and sometimes complete access to critical data.
Template:
id: CVE-2022-21371
info:
name: Oracle WebLogic Server Local File Inclusion
author: paradessia,narluin
severity: high
description: An easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0
HackerOne
CVE-2022-21371: Oracle WebLogic Server Local File Inclusion
hackerone·2024-03-04·CVSS 7.5
CVE-2022-21371 [HIGH] CVE-2022-21371: Oracle WebLogic Server Local File Inclusion
CVE-2022-21371: Oracle WebLogic Server Local File Inclusion
A vulnerability was identified in Oracle WebLogic Server, specifically in its Web Container component. The affected versions include ██████████, ██████████, ██████████, and ██████████ This vulnerability can be exploited by an unauthenticated attacker over HTTP, potentially leading to unauthorized access to critical data or complete control over Oracle WebLogic Server. The issue involves local file inclusion, which enables attackers to access sensitive data or the entire data store of the server.
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19·CVSS 8.8
CVE-2021-20166 [HIGH] Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Yue Guan
Published: August 19, 2022
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-20166
CVE-2021-20167
CVE-2021-21881
CVE-2021-24762
CVE-2021-28169
CVE-2021-31589
CVE-2021-39226
CVE-2021-4045
CVE-2021-43711
CVE-2022-21371
CVE-2022-21662
CVE-2022-22536
CVE-2022-22947
CVE-2022-22954
CVE-2022-22963
CVE-2022-22965
CVE-2022-24112
CVE-2022-24260
CVE-2022-25060
CVE-2022-25075
CVE-2022-25134
CVE-2022-27226
CVE-2022-29464
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders includ
http://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2022-01-19
Published
Exploited in the wild