cbcvebase.
CVE-2015-4852
published 2015-11-18

CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.03%
99.9th percentile
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Affected

6 ranges
VendorProductVersion rangeFixed in
oraclestoragetek_tape_analytics_sw_tool
oraclevirtual_desktop_infrastructure<= 3.5.2
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

port7001
pathoracle_common/modules/com.bea.core.apache.commons.collections.jar
snort
Apache.Commons.Collection.InvokerTransformer.Code.Execution
  • Monitor T3 protocol traffic to TCP port 7001 on Oracle WebLogic servers for crafted serialized Java objects indicative of deserialization exploitation attempts.
  • Alert on the Fortinet IPS signature 'Apache.Commons.Collection.InvokerTransformer.Code.Execution' for active exploitation of CVE-2015-4852 in HTTP-based Java applications (WebLogic, WebSphere, JBoss).
  • Look for ping beaconing with specially crafted data patterns as a vulnerability confirmation step used by attackers post-exploitation.
  • Detect Perl IRCBot payloads masquerading as Apache httpd processes connecting outbound on port 25 after being downloaded to /tmp.
  • Detect VBScript payloads checking for the '360rp' antivirus process and downloading secondary payloads (new.cvs → mc.vbs) as part of post-exploitation activity.
  • ·The blacklist-based fix can be circumvented through alternative deserialization paths (e.g., weblogic.jms.common.StreamMessageImpl using PayloadStream), so blacklist-only defenses are insufficient without the full patch chain.
  • ·Exploitation rate was observed at approximately 400 triggers/day from 50 different FortiGates over two months post-disclosure, confirming active in-the-wild exploitation with no signs of decreasing.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.