EXPOSURES › CVE-2023-21839
CVE-2023-21839
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server T3/IIOP RCE vulnerability exploited in the wild
An unspecified vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3/IIOP to compromise the server. This is a historically high-risk asset, and compliance officers should ensure strict network segmentation, continuous patching, and rigorous vulnerability management. The vulnerability is actively exploited in the wild, posing a significant risk to DIB organizations.
Shame score — Historically high-risk asset with a severe and recurring security track record, exploited in the wild, and lacking continuous patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |