668
VMScore

CVE-2021-2135

Published: 22/04/2021 Updated: 08/12/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle weblogic server 12.2.1.3.0

oracle weblogic server 12.2.1.4.0

oracle weblogic server 14.1.1.0.0

Github Repositories

Some high-quality CVEs I got CVE-2020-14756 CVE-2021-2135 CVE-2021-2136 CVE-2022-21420

Java漏洞分析汇合

JavaVulnSummary 用来练习Java代码审计的集合。 分析文章 代码地址 由JDK7u21反序列化漏洞引起的对TemplatesImpl的深入学习 githubcom/R17a-17/JavaVulnSummary/tree/main/ysoserial/src/main/java/com/r17a/ysoserial/jdk7u21 关于JDK7u21 Gadgets两个问题的探讨 githubcom/R17a-17/JavaVulnSummary/tree/main/ysoserial/src/main/