SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2015-4852

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

KEVCRITICAL 9.8EPSS 96.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
96.03% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Weakness
CWE-502
Affected
oracle/virtual desktop infrastructure · oracle/storagetek tape analytics sw tool · oracle/weblogic server
Source
secalert_us@oracle.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2015-4852

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.