cbcvebase.
CVE-2023-21839
published 2023-01-18

CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0…

PriorityP193high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2023-05-22
Exploited in the wild
EPSS
99.81%
100.0th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected

6 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://185.172.128.146:443/bin.ps1
urlhttp://0xb9ac8092:443/bin.ps1
ip185.172.128.146
ip89.185.85.102
domaingod.sck-dns.cc
hashf4d11b36a844a68bf9718cf720984468583efa6664fc99966115a44b9a20aa33
hash0bf87b0e65713bf35c8cf54c9fa0015fa629624fd590cb4ba941cd7cdeda8050
hashb380b771c7f5c2c26750e281101873772e10c8c1a0d2a2ff0aff1912b569ab93
hash2e32c5cea00f8e4c808eae806b14585e8672385df7449d2f6575927537ce8884
filenamewireguard2-3.exe
filenamemicrosoft_office365.bat
filenamebin.ps1
mutex6cbe41284f6a992cc0534b
pathC:\Users\$USERNAME$\AppData\Roaming\Name\IsSynchronized.exe
registryHKEY_CURRENT_USER\SOFTWARE\
port9091
port7001
command0.0.0.0/0 * 7001 deny t3 t3s
bytes
AES Key: 5D8D6871C3D59D855616603F686713AC48BF2351F6182EA282E1D84CBB15B94F / AES IV: CAAD009AC0881FE2A89F80CEEA6D1B6
  • Detect exploitation of CVE-2023-21839 via T3/IIOP protocol: monitor for unauthenticated inbound connections on port 7001 using T3 or IIOP, especially crafted JNDI/LDAP referral requests using the weblogic.deployment.jms.ForeignOpaqueReference class.
  • Hunt for Water Sigbin's hex-encoded URL technique: attackers encode C2 IP addresses in hexadecimal (e.g., 0xb9ac8092 = 185.172.128.146) within PowerShell IEX download cradles to evade URL-based detection.
  • Detect HTTP traffic over port 443 (non-TLS) as a stealthy C2 channel used by Water Sigbin to blend with HTTPS traffic.
  • Alert on creation of a process named cvtres.exe spawned from non-standard parent processes or from the path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe as a sign of process injection by the second-stage loader.
  • Detect fileless execution via .NET reflection in PowerShell: look for use of [System.Reflection.Assembly] combined with AES decryption and GZip decompression in PowerShell scripts, indicative of in-memory payload loading.
  • Hunt for the mutex value 6cbe41284f6a992cc0534b as an indicator of active PureCrypter loader infection on a host.
  • Monitor for scheduled tasks registered under Microsoft\Windows\Name folder configured to run at startup/login, and for Add-MpPreference exclusion commands targeting AppData\Roaming\Name\IsSynchronized.exe.
  • Check Point IPS signature available for this CVE: 'Oracle WebLogic Server Improper Access Control (CVE-2023-21839)'.
  • ·The PureCrypter loader version observed is V6.0.7D; the AES key/IV and mutex are specific to this campaign sample and may change across versions or campaigns.
  • ·All payloads are protected with .NET Reactor obfuscation and incorporate anti-debugging techniques, which may hinder static analysis and signature-based detection.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.