⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..

CVE-2015-4852Deserialization of Untrusted Data in Oracle Virtual Desktop Infrastructure

Severity
9.8CRITICALNVD
EPSS
92.8%
top 0.23%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 18
KEV addedNov 3
KEV dueMay 3
Latest updateDec 5
CISA Required Action: Apply updates per vendor instructions.

Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7r6v-mxc2-pg49: The WLS Security component in Oracle WebLogic Server 102022-05-14
OSV
CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 102015-11-18
CVEList
CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 102015-11-18
VulnCheck
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability2015

💥Exploits & PoCs

3
Exploit-DB
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)2019-03-28
Exploit-DB
Oracle WebLogic Server 10.3.6.0 - Java Deserialization Remote Code Execution2017-09-27
Exploit-DB
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution2016-07-20

🔍Detection Rules

1
Suricata
ET EXPLOIT Oracle Weblogic Server Deserialization RCE T3 (CVE-2015-4852)2022-02-15

📋Vendor Advisories

2
Ubuntu
Apache Commons Collections vulnerability2024-07-31
CISA
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability2021-11-03

🕵️Threat Intelligence

2
Recorded Future
The Bug That Won't Die: 10 Years of the Same Mistake2025-12-05
Fortinet
Apache Commons Collections Under Attack2016-02-04
CVE-2015-4852 — Deserialization of Untrusted Data | cvebase