Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-4852

Опубликовано: 18 нояб. 2015
Источник: ubuntu
Приоритет: high
CVSS2: 7.5
CVSS3: 9.8

Описание

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

РелизСтатусПримечание
artful

not-affected

3.2.2-1
bionic

not-affected

3.2.2-1
cosmic

not-affected

3.2.2-1
devel

not-affected

3.2.2-1
disco

not-affected

3.2.2-1
eoan

not-affected

3.2.2-1
esm-apps/bionic

not-affected

3.2.2-1
esm-apps/focal

not-affected

3.2.2-1
esm-apps/jammy

not-affected

3.2.2-1
esm-apps/noble

not-affected

3.2.2-1

Показывать по

РелизСтатусПримечание
artful

not-affected

4.1-1
bionic

not-affected

4.1-1
cosmic

not-affected

4.1-1
devel

not-affected

4.1-1
disco

not-affected

4.1-1
eoan

not-affected

4.1-1
esm-apps/bionic

not-affected

4.1-1
esm-apps/focal

not-affected

4.1-1
esm-apps/jammy

not-affected

4.1-1
esm-apps/noble

not-affected

4.1-1

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
disco

not-affected

code not present
eoan

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored]
esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored]
esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

cosmic

ignored

devel

ignored

disco

ignored

eoan

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-apps/noble

ignored

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 10 лет назад

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVSS3: 9.8
github
больше 3 лет назад

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

fstec
около 10 лет назад

Уязвимость сервера приложений Oracle WebLogic Server, позволяющая нарушителю выполнить произвольный код

suse-cvrf
8 месяцев назад

Security update for apache-commons-beanutils

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2015-4852