APP: Oracle WebLogic Server Commons-Collections Library Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against Oracle WebLogic Server. A successful attack can lead to arbitrary code execution.

Extended Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Affected Products

Oracle storagetek_tape_analytics_sw_tool

References

CVE: CVE-2015-4852

Short Name
APP:ORACLE:WEBLOGIC-SRV-RCE
Severity
Major
Recommended
False
Recommended Action
None
Category
APP
Keywords
CVE-2015-4852 Commons-Collections Deserialization Insecure Library Oracle Server WebLogic
Release Date
01/21/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3662
Port
tcp/7001
False Positive
Unknown
Vendors

Oracle

CVSS Score

7.5

Found a potential security threat?