Junglewise Threat Intelligence

CVE-2015-4852: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

CVE-2015-4852 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains a deserialization vulnerability in the WLS Security component. Remote attackers can execute arbitrary commands via crafted serialized Java objects in T3 protocol traffic to TCP port 7001, leveraging the Apache Commons Collections library.

Affected products

  • Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, 12.2.1.0

Timeline

  • 2015-11-06: disclosed: Public disclosure of the vulnerability via Foxglove Security blog.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: other: NVD publication date.

Related threats