漏洞描述 2021年7月Oracle官方发布关键补丁更新CVE-2021-2394,其中SerializationHelper类存在反序列化漏洞。该漏洞允许未经身份验证的攻击者通过IIOP,T3进行网络访问,未经身份验证的攻击者成功利用此漏洞可能接管OracleWeblogic Server。
相关漏洞推荐 CVE-2017-10271: WebLogic XMLDecoder 反序列化漏洞 CVE-2017-10271 POC 2025-09-01 | WebLogic XMLDecoder Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent - WL... CVE-2020-14750: Oracle WebLogic Server - Remote Command Execution POC 2025-09-01 | Oracle WebLogic Server Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 is susceptible ... CVE-2020-14883: Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution POC 2025-09-01 | Oracle Fusion Middleware WebLogic Server Administration Console The Oracle Fusion Middleware WebLogic Server admin console in versions 10.3.6.0.0, 12.1.3.0.0, 12.2.... ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...