{"id":18228,"date":"2021-01-21T00:24:03","date_gmt":"2021-01-20T23:24:03","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=18228"},"modified":"2021-01-21T00:24:03","modified_gmt":"2021-01-20T23:24:03","slug":"oracle-weblogic-rce-schwachstelle-cve-2021-2109","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/01\/21\/oracle-weblogic-rce-schwachstelle-cve-2021-2109\/","title":{"rendered":"Oracle Weblogic RCE vulnerability CVE-2021-2109"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/01\/21\/oracle-weblogic-rce-schwachstelle-cve-2021-2109\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]There is a serious remote code execution (RCE) vulnerability CVE-2021-2109 in Oracle WebLogic Server that allows the server to be taken over. Oracle released a patch to close the vulnerability in January 2021. <\/p>\n<p><!--more--><\/p>\n<p>I became aware of the issue via a <a href=\"https:\/\/twitter.com\/pyn3rd\/status\/1351696768065409026\" target=\"_blank\" rel=\"noopener\">tweet<\/a>, though the web page in question is in Chinese, so it's going to be difficult with the details. <\/p>\n<p><a href=\"https:\/\/twitter.com\/pyn3rd\/status\/1351696768065409026\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Oracle Weblogic RCE Vulnerability CVE-2021-2109\" alt=\"Oracle Weblogic RCE Vulnerability CVE-2021-2109\" src=\"https:\/\/i.imgur.com\/oOVuZSf.png\"><\/a><\/p>\n<p>Tenable&nbsp; has compiled some information in <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2021-2109\" target=\"_blank\" rel=\"noopener\">this short post<\/a>. There is a vulnerability CVE-2021-2109 in Oracle WebLogic Server of Oracle Fusion Middleware (component: Console). The following versions are affected:<\/p>\n<ul>\n<li>10.3.6.0.0\n<li>12.1.3.0.0\n<li>12.2.1.3.0\n<li>12.2.1.4.0\n<li>14.1.1.0.0<\/li>\n<\/ul>\n<p>The vulnerability is easily exploitable and allows highly privileged attackers with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks against this vulnerability can lead to the takeover of Oracle WebLogic Server. The vulnerability has been assigned a CVSS 3.1 Base Score of 7.2 (max. 10). Oracle has issued <a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2021.html\" target=\"_blank\" rel=\"noopener\">this update advisory<\/a> in January 2021, which also addresses the vulnerability.&nbsp; <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]There is a serious remote code execution (RCE) vulnerability CVE-2021-2109 in Oracle WebLogic Server that allows the server to be taken over. Oracle released a patch to close the vulnerability in January 2021.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-18228","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=18228"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/18228\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=18228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=18228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=18228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}