Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7r6v-mxc2-pg49

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

EPSS

Процентиль: 100%
0.92849
Критический

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-77

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 10 лет назад

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVSS3: 9.8
nvd
около 10 лет назад

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

fstec
около 10 лет назад

Уязвимость сервера приложений Oracle WebLogic Server, позволяющая нарушителю выполнить произвольный код

suse-cvrf
8 месяцев назад

Security update for apache-commons-beanutils

EPSS

Процентиль: 100%
0.92849
Критический

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-77