Junglewise Threat Intelligence

CVE-2017-3506: Oracle WebLogic Server OS Command Injection Vulnerability

CVE-2017-3506 · Severity: critical · CVSS 7.4 · Exploited in the wild · Published 2024-06-03

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains an OS command injection vulnerability in the Web Services subcomponent. An unauthenticated attacker can execute arbitrary code via specially crafted HTTP requests containing malicious XML documents, potentially leading to complete compromise of the server data.

Affected products

  • Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, 12.2.1.2

Timeline

  • 2017-04-18: patched: Oracle Critical Patch Update Advisory - April 2017
  • 2024-06-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats