{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aoracleweblogic_server12.2.1.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2023-21839"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WebLogic Server (12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Oracle"],"content_html":"\u003cp\u003eCVE-2023-21839 is a high-severity (CVSS 7.5) improper access control vulnerability in Oracle WebLogic Server. The vulnerability allows unauthenticated, remote attackers to trigger unauthorized JNDI lookups by manipulating objects bound via the T3 or IIOP protocols. Specifically, when an attacker triggers a lookup or list operation on a bound object, the system inadvertently invokes the getReferent method of that object. This allows an attacker to direct the server to interact with arbitrary JNDI endpoints, such as malicious LDAP servers, which can be leveraged for further exploitation. The recent publication of functional proof-of-concept exploits and scanning tools on public repositories significantly elevates the risk for organizations running affected versions (12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0). Defenders should prioritize patching and monitoring network traffic for anomalous T3/IIOP interactions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-exposed Oracle WebLogic Server instance using the T3 or IIOP protocol.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the WebLogic RMI/CORBA interface to bind a malicious or specifically crafted object to the naming service.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a JNDI lookup or list operation targeting the previously bound object.\u003c/li\u003e\n\u003cli\u003eThe WebLogic server processes the request, traversing the \u003ccode\u003eWLNamingManager\u003c/code\u003e and \u003ccode\u003eBasicNamingNode\u003c/code\u003e components.\u003c/li\u003e\n\u003cli\u003eThe application code executes the vulnerable \u003ccode\u003egetReferent\u003c/code\u003e method on the crafted object due to insufficient access controls.\u003c/li\u003e\n\u003cli\u003eThe server initiates a network connection to an attacker-controlled remote server (e.g., via \u003ccode\u003eldap://\u003c/code\u003e) as specified in the JNDI lookup.\u003c/li\u003e\n\u003cli\u003eThe external server provides a malicious payload or response to the WebLogic server, potentially leading to further exploitation or unauthorized data access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to perform unauthorized JNDI operations against Oracle WebLogic Server. If successful, this can lead to unauthorized information disclosure or serve as an initial vector for more complex attacks, including remote code execution depending on the subsequent JNDI response handling. With multiple functional exploits now publicly available, the risk to unpatched enterprise infrastructure is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eApply the latest security patches for Oracle WebLogic Server provided by Oracle immediately to remediate CVE-2023-21839.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and access control lists (ACLs) to limit access to T3 and IIOP ports (typically 7001) to known and authorized source IP addresses only.\u003c/li\u003e\n\u003cli\u003eConfigure WebLogic security policies to disable or restrict the use of JNDI lookups from untrusted sources.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous outbound connections originating from WebLogic application servers to external/unknown IP addresses, particularly over non-standard or LDAP-related ports.\u003c/li\u003e\n\u003cli\u003eAudit application logs for \u003ccode\u003ejavax.naming.InitialContext\u003c/code\u003e lookup errors or unusual JNDI activity patterns associated with RMI/IIOP services.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T12:43:23Z","date_published":"2026-09-02T12:43:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-21839/","summary":"CVE-2023-21839 is an improper access control vulnerability in Oracle WebLogic Server enabling unauthorized remote JNDI lookups via T3 or IIOP protocols, with multiple functional proof-of-concept exploits now publicly available.","title":"Oracle WebLogic Server Improper Access Control Vulnerability (CVE-2023-21839)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-21839/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}