S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Dec 8, 2025

CVE-2021-2135 Scanner

CVE-2021-2135 Scanner - Remote Code Execution vulnerability in Oracle WebLogic Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-2135
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
12.2.1.3.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebLogic Server is widely used across various organizations as a Java EE application server for building distributed and component-based enterprise applications. It caters to businesses needing reliable middleware for creating scalable and secure applications. This software is particularly popular in internet-centric enterprises requiring Java-based applications to be deployed across their systems. Oracle's robust platform offers tools for system integration, web services, and more. Both small and large-scale enterprises utilize WebLogic for its customizable and comprehensive middleware solutions. Typically, IT departments and developers are responsible for deploying and managing this service within their infrastructure.

The Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server is a critical flaw that allows unauthorized users to execute arbitrary commands on a server remotely. Exploiting this vulnerability can enable attackers to bypass authentication controls and gain unauthorized access. Identified as CVE-2021-2135, it affects specific versions of WebLogic, posing significant security risks. The potential impact includes full server takeover by malicious actors, leading to compromised data and disrupted services. Due to ease of access, such vulnerabilities are continually targeted by attackers aiming to exploit enterprise infrastructures. Effective mitigation involves regular updates and patches to prevent successful exploitation.

The remote code execution in Oracle WebLogic Server occurs via an unauthenticated endpoint accessible over T3 and IIOP protocols. Attackers exploit this by sending crafted requests that bypass authentication to execute arbitrary code. The flaw exists within Oracle WebLogic's handling of certain serialized objects, which attackers manipulate to trigger RCE. Parameters vulnerable to exploitation include network-exposed endpoints and serialization methods lacking adequate validation. Attackers utilize crafted payloads that exploit deserialization vulnerabilities, leading to unauthorized code execution. Identifying this vulnerability necessitates examining request payloads and endpoint behaviors for anomalies indicating RCE attempts.

Exploiting the RCE vulnerability allows attackers to control the affected Oracle WebLogic Server entirely. Once compromised, attackers can exfiltrate sensitive data, disrupt ongoing services, and deploy malware or additional malicious payloads. This level of access can serve as a launchpad for lateral movement within an organization's network, compromising additional systems. Data integrity and confidentiality risks escalate significantly if exploited, often leading to regulatory breaches and financial losses. Organizations must treat such vulnerabilities urgently to prevent adversaries from leveraging them for widespread attacks.

REFERENCES

Solution Advice
  • Update to the latest patched version of Oracle WebLogic Server to mitigate the vulnerability.
  • Apply security patches available at Oracle's official website to fix known vulnerabilities.
  • Restrict network access to critical components of WebLogic Server to minimize exposure.
  • Regularly monitor and audit network traffic for anomalous activities or unauthorized access attempts.
  • Implement comprehensive security practices, including intrusion detection systems and regular security assessments.
  • Train IT personnel to recognize and respond swiftly to security incidents related to WebLogic Server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-2135 Scanner - Remote Code Execution vulnerability in Oracle WebLogic Server S4E