漏洞描述 2021年7月Oracle官方发布关键补丁更新CVE-2021-2394,其中SerializationHelper类存在反序列化漏洞。该漏洞允许未经身份验证的攻击者通过IIOP,T3进行网络访问,未经身份验证的攻击者成功利用此漏洞可能接管OracleWeblogic Server。
相关漏洞推荐 weblogic-ssrf: weblogic ssrf Weblogic uddiexplorer 服务端请求伪造漏洞(CVE-2014-4210) POC CVE-2014-4210: Oracle Weblogic - Server-Side Request Forgery POC CVE-2017-10271: Oracle WebLogic Server - Remote Command Execution POC CVE-2017-3506: Oracle Fusion Middleware Weblogic Server - Remote OS Command Execution POC CVE-2018-2894: Oracle WebLogic Server - Remote Code Execution POC CVE-2019-2725: Oracle WebLogic Server - Remote Command Execution POC CVE-2019-2729: Oracle WebLogic Server Administration Console - Remote Code Execution POC CVE-2020-14750: Oracle WebLogic Server - Remote Command Execution POC CVE-2020-14882: Oracle Weblogic Server - Remote Command Execution POC CVE-2020-14883: Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution POC CVE-2020-2551: Oracle WebLogic Server - Remote Code Execution POC CVE-2022-21371: Oracle WebLogic Server Local File Inclusion