CVE-2024-21182

Published Jul 16, 2024

Last updated 7 months ago

Overview

Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Source
secalert_us@oracle.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. 🚨Alert🚨 CVE-2024-21182 : Allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server 🔥PoC : https://t.co/F70QGGpWpc 📊 2.6m+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/sCnTqGaKO6 👇Query HUNTER… h

    @HunterMapping

    2 Jan 2025

    6527 Impressions

    43 Retweets

    125 Likes

    81 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-21182 impacts Oracle WebLogic Server (12.2.1.4.0 & 14.1.1.0.0). Rated CVSS 7.5 (High), it allows unauthenticated remote attacks via T3/IIOP protocols. Easily exploitable, it risks exposing sensitive or full server data. #InfoSec #CyberSecurity https://t.co/OJkBj5v

    @SaifuddinAmri__

    1 Jan 2025

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. به تازگی آسیب پذیری جدیدی با کد شناسایی  CVE-2024-21182 برای محصول Oracle WebLogic Server منتشر شده است. این آسیب پذیری که مربوط به نسخه های 12.2.1.4.0 تا 14.1.1.0.0 می باشد ، به هکرها امکان اجرای کد و دسترسی کامل بر روی سیستم آسیب پذیر را می دهد. https://t.co/Poz3aKYxT1 https://

    @AmirHossein_sec

    1 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. PoC Exploit Code Published for Severe WebLogic Flaw (CVE-2024-21182) https://t.co/86A3vuLF8R

    @TMJIntel

    1 Jan 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-21182: PoC Exploit Code Published for Severe WebLogic Flaw - https://t.co/kXK0nfNjts

    @moton

    1 Jan 2025

    93 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Top 5 Trending CVEs: 1 - CVE-2024-49128 2 - CVE-2024-21182 3 - CVE-2024-3094 4 - CVE-2024-12744 5 - CVE-2024-38472 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Jan 2025

    107 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-21182: PoC Exploit Code Published for Severe WebLogic Flaw Learn about the proof-of-concept (PoC) exploit for CVE-2024-21182 in Oracle WebLogic Server. Understand the risks and take action to secure your server. https://t.co/Yh8TTwTLPH

    @the_yellow_fall

    1 Jan 2025

    311 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. 🗣 CVE-2024-21182: PoC Exploit Code Published for Severe WebLogic Flaw https://t.co/Td5GS207Z0

    @fridaysecurity

    1 Jan 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-21182: Oracle WebLogic Server Zafiyeti, Uzaktan Kod Çalıştırmaya Olanak Tanıyor! https://t.co/G86GCyEiCc

    @cyberwebeyeos

    31 Dec 2024

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-21182: Oracle WebLogic Server Flaw Exploit Code Released #OracleWeblogic #CVE-2024-21182 #ExploiCode https://t.co/9RT6LvVTOO

    @pravin_karthik

    31 Dec 2024

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. به تازگی آسیب پذیری جدیدی باکد شناسایی  CVE-2024-21182برای محصول Oracle WebLogic Server منتشر شده است.این آسیب پذیری که مربوط به نسخه های 12.2.1.4.0 تا 14.1.1.0.0 این محصول می باشد،به سادگی اکسپلویت می شودو به هکرها امکان اجرای کد و دسترسی کامل بر روی سیستم آسیب پذیر را می دهد.

    @cybernetic_cy

    31 Dec 2024

    151 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 New PoC Alert: CVE-2024-21182 - Oracle WebLogic Server JNDI Vulnerability 🚨 ✅ Risk: High 📈 Impact: Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. 🚨 CVSS: 7.5 🔗…

    @gothburz

    30 Dec 2024

    182 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ثغرة خطيرة في Oracle WebLogic Server تُهدد أمان التطبيقات المؤسسية 🛑 رقم الثغرة: CVE-2024-21182 📜 الوصف: تم الكشف عن Proof-of-Concept (PoC) لاستغلال ثغرة حرجة في Oracle WebLogic Server. هذه الثغرة تُتيح للمهاجمين غير المصرح لهم الذين يمتلكون وصولًا إلى الشبكة استغلال النظام… h

    @MahRabie

    30 Dec 2024

    136 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Oracle WebLogicの脆弱性CVE-2024-21182に対応するPoC(攻撃の概念実証コード)が公表された。T3及びIIOP (Internet Inter-ORB Protocol)経由での悪用が容易に可能。 https://t.co/5d7D8J44wl

    @__kokumoto

    30 Dec 2024

    686 Impressions

    1 Retweet

    3 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  15. Oracle WebLogic Server JNDI Vulnerability CVE-2024-21182 https://t.co/3mv3IpwhUV

    @momika233

    30 Dec 2024

    2826 Impressions

    14 Retweets

    59 Likes

    23 Bookmarks

    1 Reply

    0 Quotes

Configurations