⚠ Actively exploited
Added to CISA KEV on 2023-05-01. Federal agencies required to patch by 2023-05-22. Required action: Apply updates per vendor instructions..

CVE-2023-21839Deserialization of Untrusted Data in Corporation Weblogic Server

Severity
7.5HIGHNVD
EPSS
94.1%
top 0.09%
CISA KEV
KEV
Added 2023-05-01
Due 2023-05-22
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 18
KEV addedMay 1
KEV dueMay 22
Latest updateOct 27
CISA Required Action: Apply updates per vendor instructions.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Co

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDoracle/weblogic_server12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0+2
CVEListV5oracle_corporation/weblogic_server12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f8x3-c29w-wfmj: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)2023-01-18
CVEList
CVE-2023-21839: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)2023-01-17
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability2023

💥Exploits & PoCs

1
Nuclei
Oracle WebLogic Server - Unauthorized Access

🔍Detection Rules

1
Suricata
ET WEB_SERVER Oracle WebLogic Unauthenticated IIOP/T3 Remote Code Execution (CVE-2023-21839)2025-10-27

📋Vendor Advisories

2
CISA
Oracle WebLogic Server Unspecified Vulnerability2023-05-01
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2023-218392023-01-15

🕵️Threat Intelligence

6
Trendmicro
Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer2024-06-28
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks2024-05-30
Trendmicro
Decoding Water Sigbin's Latest Obfuscation Tricks2024-05-30
Sentinelone
CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory2023-03-03
Sentinelone
CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory2023-03-03
CVE-2023-21839 — Deserialization of Untrusted Data | cvebase