CVE-2015-4852
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.5.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.3 | |
| Version 10.3.6.0.0 |
References (31)
Source: secalert_us@oracle.com
Exploit
Source: secalert_us@oracle.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Patch
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Vendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Broken Link
Source: secalert_us@oracle.com
Product
Source: secalert_us@oracle.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.