CyberSec.Space Logo
Back to CVE Browser

CVE-2015-4852

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score93.7870%
EPSS Percentile95.58th
PublishedNov 18, 2015
Last ModifiedApr 21, 2026

Vulnerability Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Affected Platforms (CPE)

πŸ“¦
Oracle

Virtual Desktop Infrastructure

<= 3.5.2
πŸ“¦
Oracle

Storagetek Tape Analytics Sw Tool

= 2.3
πŸ“¦
Oracle

Weblogic Server

= 10.3.6.0.0
πŸ“¦
Oracle

Weblogic Server

= 12.1.2.0.0
πŸ“¦
Oracle

Weblogic Server

= 12.1.3.0.0
πŸ“¦
Oracle

Weblogic Server

= 12.2.1.0.0

References & Advisories

Related Vulnerabilities