CVE-2015-4852
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.03% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-502
- Affected
- oracle/virtual desktop infrastructure · oracle/storagetek tape analytics sw tool · oracle/weblogic server
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2015-4852
References
- http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/Exploit
- http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/11/17/19Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/77539Broken Link
- http://www.securitytracker.com/id/1038292Broken Link
- https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852Broken Link
- https://github.com/foxglovesec/JavaUnserializeExploits/blob/master/weblogic.pyProduct
- https://www.exploit-db.com/exploits/42806/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46628/Exploit, Third Party Advisory, VDB Entry
- http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/Exploit
- http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/11/17/19Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/77539Broken Link
- http://www.securitytracker.com/id/1038292Broken Link
- https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852Broken Link
- https://github.com/foxglovesec/JavaUnserializeExploits/blob/master/weblogic.pyProduct
- https://www.exploit-db.com/exploits/42806/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46628/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.