Executive brief
Oracle WebLogic Server contains a deserialization vulnerability in the WLS Security component. Remote attackers can execute arbitrary commands via crafted serialized Java objects in T3 protocol traffic to TCP port 7001, leveraging the Apache Commons Collections library.
Affected products
- Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, 12.2.1.0
Timeline
- 2015-11-06: disclosed: Public disclosure of the vulnerability via Foxglove Security blog.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: other: NVD publication date.