Skip to content
COOEY

EXPOSURES › CVE-2023-21839

CVE-2023-21839

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-21839 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Oracle WebLogic Server T3/IIOP RCE vulnerability exploited in the wild

An unspecified vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3/IIOP to compromise the server. This is a historically high-risk asset, and compliance officers should ensure strict network segmentation, continuous patching, and rigorous vulnerability management. The vulnerability is actively exploited in the wild, posing a significant risk to DIB organizations.

Shame score — Historically high-risk asset with a severe and recurring security track record, exploited in the wild, and lacking continuous patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized