cbcvebase.
CVE-2023-21839
published 2023-01-18

CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0…

PriorityP193high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2023-05-22
Exploited in the wild
EPSS
99.90%
100.0th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected

6 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server——
oracleweblogic_server——
oracleweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://185.172.128.146:443/bin.ps1↗
urlhttp://0xb9ac8092:443/bin.ps1↗
ip185.172.128.146↗
ip89.185.85.102↗
domaingod.sck-dns.cc↗
hashf4d11b36a844a68bf9718cf720984468583efa6664fc99966115a44b9a20aa33↗
hash0bf87b0e65713bf35c8cf54c9fa0015fa629624fd590cb4ba941cd7cdeda8050↗
hashb380b771c7f5c2c26750e281101873772e10c8c1a0d2a2ff0aff1912b569ab93↗
hash2e32c5cea00f8e4c808eae806b14585e8672385df7449d2f6575927537ce8884↗
filenamewireguard2-3.exe↗
filenamemicrosoft_office365.bat↗
filenamebin.ps1↗
mutex6cbe41284f6a992cc0534b↗
pathC:\Users\$USERNAME$\AppData\Roaming\Name\IsSynchronized.exe↗
registryHKEY_CURRENT_USER\SOFTWARE\↗
port9091↗
port7001↗
command0.0.0.0/0 * 7001 deny t3 t3s↗
bytes↗
AES Key: 5D8D6871C3D59D855616603F686713AC48BF2351F6182EA282E1D84CBB15B94F / AES IV: CAAD009AC0881FE2A89F80CEEA6D1B6
  • →Detect exploitation of CVE-2023-21839 via T3/IIOP protocol: monitor for unauthenticated inbound connections on port 7001 using T3 or IIOP, especially crafted JNDI/LDAP referral requests using the weblogic.deployment.jms.ForeignOpaqueReference class. ↗
  • →Hunt for Water Sigbin's hex-encoded URL technique: attackers encode C2 IP addresses in hexadecimal (e.g., 0xb9ac8092 = 185.172.128.146) within PowerShell IEX download cradles to evade URL-based detection. ↗
  • →Detect HTTP traffic over port 443 (non-TLS) as a stealthy C2 channel used by Water Sigbin to blend with HTTPS traffic. ↗
  • →Alert on creation of a process named cvtres.exe spawned from non-standard parent processes or from the path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe as a sign of process injection by the second-stage loader. ↗
  • →Detect fileless execution via .NET reflection in PowerShell: look for use of [System.Reflection.Assembly] combined with AES decryption and GZip decompression in PowerShell scripts, indicative of in-memory payload loading. ↗
  • →Hunt for the mutex value 6cbe41284f6a992cc0534b as an indicator of active PureCrypter loader infection on a host. ↗
  • →Monitor for scheduled tasks registered under Microsoft\Windows\Name folder configured to run at startup/login, and for Add-MpPreference exclusion commands targeting AppData\Roaming\Name\IsSynchronized.exe. ↗
  • →Check Point IPS signature available for this CVE: 'Oracle WebLogic Server Improper Access Control (CVE-2023-21839)'. ↗
  • ·The PureCrypter loader version observed is V6.0.7D; the AES key/IV and mutex are specific to this campaign sample and may change across versions or campaigns. ↗
  • ·All payloads are protected with .NET Reactor obfuscation and incorporate anti-debugging techniques, which may hinder static analysis and signature-based detection. ↗

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.