References https://nvd.nist.gov/vuln/detail/cve-2023-21931 https://avd.aliyun.com/detail?id=AVD-2023-21931 https://github.com/gobysec/Weblogic/blob/main/WebLogic_CVE-2023-21931_zh_CN.md https://github.com/gobysec/Weblogic/blob/main/WebLogic_CVE-2023-21931_en_US.md https://isecurity.huawei.com/sec/web/viewAlert.do?id=2452 https://www.secpulse.com/archives/199250.html https://blog.csdn.net/2401_84911544/article/details/138936468 https://www.ctfiot.com/110544.html https://www.oracle.com/security-alerts/cpuapr2023.html https://www.sentinelone.com/vulnerability-database/cve-2023-21931/ https://www.tenable.com/cve/CVE-2023-21931/plugins https://access.redhat.com/security/cve/cve-2023-21931
Related VulnerabilitiesPoCCVE-2026-35273: Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCEWebLogic Server Proxy Plug-in 存在远程命令执行漏洞(CVE-2026-21962)PoCCVE-2020-9314: Oracle iPlanet Web Server 7.0.x - Image InjectionPoCoracle-ebs-sqllog-exposure: Oracle EBS SQL Log - ExposurePoCCVE-2021-2135: Oracle WebLogic Server - Remote Code ExecutionOracle Identity Manager /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 命令执行漏洞(CVE-2025-61757)Oracle Identity Manager 访问控制不当漏洞PoCCVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication BypassOracle_E_Business 存在SSRF(CVE-2025-61884)(CVE-2025-61757)Oracle Identity Manager REST WebServices远程接管漏洞(CVE-2025-61884) Oracle配置器运行时UI未授权访问漏洞