GobyVuls/CVE-2023-21931.md
Goby 3c4eb4259d
Create CVE-2023-21931.md
add CVE-2023-21931
2023-04-19 04:50:04 +08:00

2.6 KiB
Raw Blame History

Weblogic LinkRef Deserialization Remote Code Execution Vulnerability (CVE-2023-21931)

Vulnerability Weblogic LinkRef Deserialization Remote Code Execution Vulnerability (CVE-2023-21931)
Chinese name Weblogic LinkRef 反序列化远程代码执行漏洞CVE-2023-21931
CVSS core 7.5
FOFA Query (click to view the results directly) (body="Welcome to WebLogic Server") || (title=="Error 404--Not Found") || (((body="<h1>BEA WebLogic Server" || server="Weblogic" || body="content="WebLogic Server" || body="<h1>Welcome to Weblogic Application" || body="<h1>BEA WebLogic Server") && header!="couchdb" && header!="boa" && header!="RouterOS" && header!="X-Generator: Drupal") || (banner="Weblogic" && banner!="couchdb" && banner!="drupal" && banner!=" Apache,Tomcat,Jboss" && banner!="ReeCam IP Camera" && banner!="<h2>Blog Comments")) || (port="7001" && protocol=="weblogic")
Number of assets affected 127237
Description WebLogic Server is one of the application server components for cloud and traditional environments.There is a remote code execution vulnerability in WebLogic, which allows an unauthenticated attacker to access and damage the vulnerable WebLogic Server through the IIOP protocol network. Successful exploitation of the vulnerability can lead to WebLogic Server being taken over by the attacker, resulting in remote code execution.
Impact There is a remote code execution vulnerability in WebLogic, which allows an unauthenticated attacker to access and damage the vulnerable WebLogic Server through the IIOP protocol network. Successful exploitation of the vulnerability can lead to WebLogic Server being taken over by the attacker, resulting in remote code execution.