SSL: IBM WebSphere Application Server Remote Code Execution 2

This signature detects attempts to exploit a known vulnerability against IBM WebSphere Application. A successful attack can lead to arbitrary code execution.

Extended Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Affected Products

Oracle storagetek_tape_analytics_sw_tool

Short Name
SSL:WS-APPSRV-RCE2
Severity
Major
Recommended
True
Recommended Action
Drop
Category
SSL
Keywords
2 Application CVE-2015-4852 CVE-2015-7450 Code Execution IBM Remote Server WebSphere bid:77653
Release Date
11/24/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3662
False Positive
Unknown
Vendors

Oracle

CVSS Score

7.5

10.0

Found a potential security threat?