CVE-2015-4852
published 2015-11-18CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.03%
99.9th percentile
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | storagetek_tape_analytics_sw_tool | — | — |
| oracle | virtual_desktop_infrastructure | <= 3.5.2 | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Apache.Commons.Collection.InvokerTransformer.Code.Execution
- →Monitor T3 protocol traffic to TCP port 7001 on Oracle WebLogic servers for crafted serialized Java objects indicative of deserialization exploitation attempts. ↗
- →Alert on the Fortinet IPS signature 'Apache.Commons.Collection.InvokerTransformer.Code.Execution' for active exploitation of CVE-2015-4852 in HTTP-based Java applications (WebLogic, WebSphere, JBoss). ↗
- →Look for ping beaconing with specially crafted data patterns as a vulnerability confirmation step used by attackers post-exploitation. ↗
- →Detect Perl IRCBot payloads masquerading as Apache httpd processes connecting outbound on port 25 after being downloaded to /tmp. ↗
- →Detect VBScript payloads checking for the '360rp' antivirus process and downloading secondary payloads (new.cvs → mc.vbs) as part of post-exploitation activity. ↗
- ·The blacklist-based fix can be circumvented through alternative deserialization paths (e.g., weblogic.jms.common.StreamMessageImpl using PayloadStream), so blacklist-only defenses are insufficient without the full patch chain. ↗
- ·Exploitation rate was observed at approximately 400 triggers/day from 50 different FortiGates over two months post-disclosure, confirming active in-the-wild exploitation with no signs of decreasing. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 WebLogic Server command injection (EDB-42806 / Nessus ID 87432)
vuldb·2026-04-22·CVSS 9.8
CVE-2015-4852 [CRITICAL] Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 WebLogic Server command injection (EDB-42806 / Nessus ID 87432)
A vulnerability was found in Oracle StorageTek Tape Analytics SW Tool up to 2.2.0 and classified as very critical. Impacted is an unknown function of the component WebLogic Server. Such manipulation leads to command injection.
This vulnerability is referenced as CVE-2015-4852. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar command injection (Exploit 152268 / EDB-42806)
vuldb·2026-04-22·CVSS 9.8
CVE-2015-4852 [CRITICAL] Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0 WLS Security com.bea.core.apache.commons.collections.jar command injection (Exploit 152268 / EDB-42806)
A vulnerability, which was classified as critical, was found in Oracle WebLogic Server 10.3.6.0/12.1.2.0/12.1.3.0/12.2.1.0. This impacts an unknown function of the file oracle_common/modules/com.bea.core.apache.commons.collections.jar of the component WLS Security Handler. The manipulation results in command injection.
This vulnerability is reported as CVE-2015-4852. The attack can be launched remotely. Moreover, an exploit is present.
Applying restrictive firewalling is recommended.
GHSA
GHSA-7r6v-mxc2-pg49: The WLS Security component in Oracle WebLogic Server 10
ghsa_unreviewed·2022-05-14
CVE-2015-4852 [HIGH] CWE-502 GHSA-7r6v-mxc2-pg49: The WLS Security component in Oracle WebLogic Server 10
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
OSV
CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 10
osv·2015-11-18·CVSS 9.8
CVE-2015-4852 [CRITICAL] CVE-2015-4852: The WLS Security component in Oracle WebLogic Server 10
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
VulnCheck
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
vulncheck·2015·CVSS 9.8
CVE-2015-4852 [CRITICAL] CWE-502 Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa20-275a; https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF; https://us-cert.cisa.gov/ncas/alerts/aa20-275a; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/bae8da7c0ecd; https://vulncheck.com/xdb/3b46068ce37d; https://vulncheck.com/xdb/d6ab148d5191; https://vulncheck.co
Ubuntu
Apache Commons Collections vulnerability
vendor_ubuntu·2024-07-31
CVE-2015-4852 Apache Commons Collections vulnerability
Title: Apache Commons Collections vulnerability
Summary: Apache Commons Collections could be made to execute arbitrary code if it
received specially crafted input.
It was discovered that Apache Commons Collections allowed serialization
support for unsafe classes by default. A remote attacker could possibly
use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
CISA
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2015-4852 [CRITICAL] CWE-502 Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Vulnerability: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Affected: Oracle WebLogic Server
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-4852
Remediation Due Date: 2022-05-03
Suricata
ET EXPLOIT Oracle Weblogic Server Deserialization RCE T3 (CVE-2015-4852)
suricata·2022-02-15·CVSS 9.8
CVE-2015-4852 [CRITICAL] ET EXPLOIT Oracle Weblogic Server Deserialization RCE T3 (CVE-2015-4852)
ET EXPLOIT Oracle Weblogic Server Deserialization RCE T3 (CVE-2015-4852)
Rule: alert tcp $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Oracle Weblogic Server Deserialization RCE T3 (CVE-2015-4852)"; flow:established,to_server; content:"|00 00|"; startswith; content:"|01 65|"; distance:2; within:2; content:"|ac ed 00|"; distance:0; content:"weblogic.rjvm.ClassTableEntry"; fast_pattern; distance:0; reference:cve,2015-4852; reference:url,www.exploit-db.com/exploits/46628; classtype:attempted-admin; sid:2035204; rev:1; metadata:created_at 2022_02_15, cve CVE_2015_4852, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_02_15;)
Suricata
ET SCAN Possible Scanning for Vulnerable JBoss
suricata·2015-12-09
CVE-2015-4852 ET SCAN Possible Scanning for Vulnerable JBoss
ET SCAN Possible Scanning for Vulnerable JBoss
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET SCAN Possible Scanning for Vulnerable JBoss"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/invoker/"; startswith; content:"servlet/"; http.request_body; content:"org.jboss.invocation.MarshalledValue"; http.content_type; content:"application/x-java-serialized-object|3b|"; endswith; reference:url,blog.imperva.com/2015/12/zero-day-attack-strikes-again-java-zero-day-vulnerability-cve-2015-4852-tracked-by-imperva.html; classtype:web-application-attack; sid:2022240; rev:4; metadata:created_at 2015_12_09, confidence Medium, signature_severity Minor, updated_at 2024_04_12;)
Exploit-DB
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
exploitdb·2019-03-28
CVE-2015-4852 Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/exploit/powershell'
class MetasploitModule 'Oracle Weblogic Server Deserialization RCE - Raw Object',
'Description' => %q{
An unauthenticated attacker with network access to the Oracle Weblogic Server T3
interface can send a serialized object (weblogic.jms.common.StreamMessageImpl)
to the interface to execute code on vulnerable hosts.
},
'Author' =>
[
'Andres Rodriguez', # Metasploit Module - 2Secure (@acamro, acamro[at]gmail.com)
'Stephen Breen', # Vulnerability Discovery
'Aaron Soto' # Reverse Engineering JSO and ysoserial blobs
],
'License' => MSF_LICENSE,
'
Exploit-DB
Oracle WebLogic Server 10.3.6.0 - Java Deserialization Remote Code Execution
exploitdb·2017-09-27·CVSS 9.8
CVE-2015-4852 [CRITICAL] Oracle WebLogic Server 10.3.6.0 - Java Deserialization Remote Code Execution
Oracle WebLogic Server 10.3.6.0 - Java Deserialization Remote Code Execution
---
# Exploit Title: [Oracle WebLogic Server Java Deserialization Remote Code Execution]
# Date: [27/09/2017]
# Exploit Author: [SlidingWindow] , Twitter: @kapil_khot
# Vulnerability Author: FoxGloveSecurity
# Vendor Homepage: [http://www.oracle.com/technetwork/middleware/weblogic/overview/index.html]
# Affetcted Versions: [Oracle WebLogic Server, versions 10.3.6.0, 12.1.2.0, 12.1.3.0 and 12.2.1.0]
# Tested on: [Oracle WebLogic Server version 10.3.6.0 running on a Docker image Ubuntu 14.04.4 LTS, Trusty Tahr]
# CVE : [CVE-2015-4852]
'''
This exploit tests the target Oracle WebLogic Server for Java Deserialization RCE vulnerability. The ysoserial payload causes the target to send
Ping requests to attacking machi
Exploit-DB
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
exploitdb·2016-07-20
CVE-2015-4852 Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
---
#!/bin/bash/env python3
#
# ____ _ _ _
# / ___| ___ _ __(_) __ _| | __ _| |_ ___ _ __
# \___ \ / _ \ '__| |/ _` | |/ _` | __/ _ \| '__|
# ___) | __/ | | | (_| | | (_| | || (_) | |
# |____/ \___|_| |_|\__,_|_|\__,_|\__\___/|_|
#
# By Nikhil Sreekumar (@roo7break)
#
import sys
import base64
import httplib2
import socket
import argparse
import socket
import os
import struct
import ctypes
version = "0.1"
banner = """
____ _ _ _
/ ___| ___ _ __(_) __ _| | __ _| |_ ___ _ __
\___ \ / _ \ '__| |/ _` | |/ _` | __/ _ \| '__|
___) | __/ | | | (_| | | (_| | || (_) | |
|____/ \___|_| |_|\__,_|_|\__,_|\__\___/|_|
by Nikhil Sreekumar (@roo7break) v %s
""" % version
def hex2raw3(teststr):
""
Metasploit
Oracle Weblogic Server Deserialization RCE - Raw Object
metasploit
Oracle Weblogic Server Deserialization RCE - Raw Object
Oracle Weblogic Server Deserialization RCE - Raw Object
An unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object (weblogic.jms.common.StreamMessageImpl) to the interface to execute code on vulnerable hosts.
Recorded Future
The Bug That Won't Die: 10 Years of the Same Mistake
blogs_recorded_future·2025-12-05·CVSS 9.8
CVE-2025-55182 [CRITICAL] The Bug That Won't Die: 10 Years of the Same Mistake
## The Bug That Won't Die:
## 10 Years of the Same Mistake
## A decade of deserialization vulnerabilities (and why we keep making them)
There are now multiple publicly available exploit scripts (I forked one on GitHub here ) for the React and Next.js vulnerabilities (CVE-2025-55182 and CVE-2025-66478).
The underlying issue is data serialization/deserialization, which evoked thoughts about a blog I wrote in 2016 , addressing the same issue (at the time, the topic was CVE-2015-4852 , a serialization flaw in Java objects that affected Oracle and Apache products).
## 2 Risk Takeaways
The exploit pattern repeats because serialization is a straightforward method for transferring data, and developers typically use what works. Coders use different languages and frameworks, yet the same class
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyberbedrohungen
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabili
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay 2021/04/28 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilities
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Minacce cyber
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Ciberamenazas
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
## How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay Apr 28, 2021 Read time: ( words)
Save to Folio
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands of new vulnerabilitie
Trendmicro
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
blogs_trendmicro·2021-04-28
Manage Zero Day Exploits (ZDI) with Trend Micro Solutions
Cyber Threats
# How Trend Micro Helps Manage Exploited Vulnerabilities
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Read how Trend Micro protects customers from vulnerability exploits by blocking them as early as possible.
By: Jon Clay
2021/04/28
Read time: ( words)
Save to Folio
Photo credit: pxhere
As technological innovations evolve, protecting companies from cyber threats tomorrow secures their businesses today. Exploiting known vulnerabilities to successfully compromise an organization has long been a common tactic used by malicious actors. Whether Heartbleed, EternalBlue, or most recently Zerologon, threat actors take advantage of newly disclosed vulnerabilities in their attacks. But even with thousands o
Tenable
Government Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities
blogs_tenable·2020-10-23
Government Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities | Qualys
blogs_qualys·2020-10-22·CVSS 9.8
CVE-2020-15505 [CRITICAL] NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities | Qualys
#### Table of Contents
- Detect 25 Publicly Known Vulnerabilities using VMDR
Update November 25, 2020: The UK National Cyber Security Centre alerts that APT nation-state groups and cybercriminals are exploiting MobileIron RCE vulnerability (CVE-2020-15505).
Original post: On October 20, 2020, the United States National Security Agency (NSA) released a cybersecurity advisory on Chinese state-sponsored malicious cyber activity. The NSA alert provided a list of 25 publicly known vulnerabilities that are known to be recently leveraged by cyber actors for various hacking operations.
“Since these techniques include exploitation of publicly known vulnerabilities, it is critical that network defenders prioritize patching and
mitigation efforts,” said the NSA advisory. It also recommended “crit
Qualys
NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities
blogs_qualys·2020-10-22·CVSS 10.0
CVE-2020-15505 [CRITICAL] NSA Alert: Chinese State-Sponsored Actors Exploit Known Vulnerabilities
## Table of Contents
Detect 25 Publicly Known Vulnerabilities using VMDR
Update November 25, 2020 : The UK National Cyber Security Centre alerts that APT nation-state groups and cybercriminals are exploiting MobileIron RCE vulnerability (CVE-2020-15505).
Original post : On October 20, 2020, the United States National Security Agency (NSA) released a cybersecurity advisory on Chinese state-sponsored malicious cyber activity. The NSA alert provided a list of 25 publicly known vulnerabilities that are known to be recently leveraged by cyber actors for various hacking operations.
“Since these techniques include exploitation of publicly known vulnerabilities, it is critical that network defenders prioritize patching and mitigation efforts,” said the NSA advisory. It also recommended “critic
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20·CVSS 9.8
[CRITICAL] Hunting for Web Shells
Blog /
Subscribe
# Hunting for Web Shells
Jacob Baines
December 20, 2016
10 Min Read
Web shells are nothing new, but their use continues to plague security professionals and their customers. With low anti-virus detection rates and few good tools to aid in discovery, how can you fight back?
### A breach has occurred
On November 25th, 900 San Francisco Municipal Transportation Agency (SFMTA) computers were infected by a ransomware variant known as HDDCryptor. The ransom demand was 100 bitcoins (approximately $73,000). Due to the attack the SFMTA was temporarily unable to collect an estimated $50,000 in fares.
"You Hacked, ALL Data Encrypted, Contact For Key([email protected])ID:601, Enter Key:"
The immediate question is: “How did this happen?” In a press release, the SFMTA stated th
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20
Hunting for Web Shells
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R1] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization Remote Code Execution
blogs_tenable·2016-04-19
[R1] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Apache Commons Collections Under Attack
blogs_fortinet·2016-02-04·CVSS 9.8
CVE-2015-4852 [CRITICAL] Apache Commons Collections Under Attack
FORTIGUARD LABS THREAT RESEARCH
Apache Commons Collections Under Attack
By Dehui Yin | February 04, 2016
Two months ago, a Java zero day vulnerability (CVE-2015-4852) that targeted Apache commons collections library was disclosed. This vulnerability is caused by an error when Java applications, which use Apache commons collections library, deserialize objects from untrusted network sources. Let’s take a look:
Our Fortinet IPS team immediately created a signature, "Apache.Commons.Collection.InvokerTransformer.Code.Execution", in order to protect our customers, and continues to monitor. Over the last 2 months, since creating the initial signature, we have seen it triggered on average, 400 times a day from 50 different FortiGates. This rate of alert is not very high, however, these alerts
Recorded Future
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis
blogs_recorded_future
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis
# Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis
Editor’s Note: Some of the analysis featured in this article utilizes real-time intelligence from our new Vulnerability Intelligence Cards™. With this summarized data you can assess, prioritize, and remediate vulnerabilities with much greater speed and confidence to reduce your risk. Find out more in the “Threat Intelligence Use Cases” section of our website.
### Key Takeaways
- Recorded Future’s programmatic identification of exploit chatter for vulnerabilities leads to improved remediation prioritization. This prioritization is based on evidence-based assessment of increased adversary intent and/or capabilities.
- Recorded Future’s foreign natural language processing (NLP) adds significant value to vulnerability
Recorded Future
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis | Recorded Future
blogs_recorded_future
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis | Recorded Future
## Turning Criminal Forum Exploit Chatter Into Vulnerability Risk Analysis
Editor’s Note : Some of the analysis featured in this article utilizes real-time intelligence from our new Vulnerability Intelligence Cards™. With this summarized data you can assess, prioritize, and remediate vulnerabilities with much greater speed and confidence to reduce your risk. Find out more in the “ Threat Intelligence Use Cases ” section of our website.
## Key Takeaways
Recorded Future’s programmatic identification of exploit chatter for vulnerabilities leads to improved remediation prioritization. This prioritization is based on evidence-based assessment of increased adversary intent and/or capabilities.
Recorded Future’s foreign natural language processing (NLP) adds significant value to vulnerability
Recorded Future
The Bug That Won't Die: 10 Years of the Same Mistake
blogs_recorded_future·CVSS 9.8
CVE-2025-55182 [CRITICAL] The Bug That Won't Die: 10 Years of the Same Mistake
# The Bug That Won't Die:
# 10 Years of the Same Mistake
## A decade of deserialization vulnerabilities (and why we keep making them)
CVE-2025-55182 Intelligence Card c/o Recorded Future
There are now multiple publicly available exploit scripts (I forked one on GitHub here) for the React and Next.js vulnerabilities (CVE-2025-55182 and CVE-2025-66478).
The underlying issue is data serialization/deserialization, which evoked thoughts about a blog I wrote in 2016, addressing the same issue (at the time, the topic was CVE-2015-4852, a serialization flaw in Java objects that affected Oracle and Apache products).
Timeline illustrating the deserialization vulnerability impacts of 40+ critical CVEs across 6 ecosystems, over the course of 10 years.
## 2 Risk Takeaways
- The exploit pattern
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2015/11/17/19http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.securityfocus.com/bid/77539http://www.securitytracker.com/id/1038292https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852https://github.com/foxglovesec/JavaUnserializeExploits/blob/master/weblogic.pyhttps://www.exploit-db.com/exploits/42806/https://www.exploit-db.com/exploits/46628/http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2015/11/17/19http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.securityfocus.com/bid/77539http://www.securitytracker.com/id/1038292https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852https://github.com/foxglovesec/JavaUnserializeExploits/blob/master/weblogic.pyhttps://www.exploit-db.com/exploits/42806/https://www.exploit-db.com/exploits/46628/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4852
2015-11-18
Published
2021-11-03
Added to CISA KEV
Exploited in the wild