
CVE-2021-1994、CVE-2021-2047、CVE-2021-2064、CVE-2021-2108、CVE-2021-2075、CVE-2019-17195、CVE-2020-14756、CVE-2021-2109
This project is intended for security research and authorized use only. Users are responsible and obligated to comply with local laws and regulations.
CVE-2021-1994, CVE-2021-2047, CVE-2021-2064, CVE-2021-2108, CVE-2021-2075, CVE-2019-17195, CVE-2020-14756, CVE-2021-2109
7 critical vulnerabilities affecting WebLogic (CVE-2021-1994, CVE-2021-2047, CVE-2021-2064, CVE-2021-2108, CVE-2021-2075, CVE-2019-17195, CVE-2020-14756). Unauthenticated attackers can achieve remote code execution through these vulnerabilities. All have a CVSS score of 9.8 with low exploitation complexity.
WebLogic Server Remote Code Execution Vulnerability (CVE-2021-2109) exists in the WebLogic Server console, with a CVSS score of 7.2. Authenticated attackers can remotely execute commands or code via JNDI injection attacks.
These vulnerabilities require either an unauthorized vulnerability or a weak login password. When there are too many IPs to test, a script was written to detect unauthorized vulnerabilities for convenience.