CVE-2015-4852
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 96% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-502
מוצרים מושפעים
oracle: virtual desktop infrastructure; oracle: storagetek tape analytics sw tool; oracle: weblogic server
קישורים
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchVendor Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.… Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchVendor Advisory
- http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.… Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html PatchVendor Advisory