CVE-2016-3510
published 2016-07-21CVE-2016-3510: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to…
PriorityP183critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
91.40%
99.8th percentile
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
016501ffffffffffffffff000000710000ea6000000018432ec6a2a63985b5af7d63e64383f42a6d92c9e9af0f9472027973720078720178720278700000000c00000002000000000000000000000001007070707070700000000c00000002000000000000000000000001007006fe010000aced00057372001d7765626c6f6769632e726a766d2e436c6173735461626c65456e7472792f52658157f4f9ed0c000078707200247765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e5061636b616765496e666fe6f723e7b8ae1ec90200094900056d616a6f724900056d696e6f7249000b706174636855706461746549000c726f6c6c696e67506174636849000b736572766963655061636b5a000e74656d706f7261727950617463684c0009696d706c5469746c657400124c6a6176612f6c616e672f537472696e673b4c000a696d706c56656e646f7271007e00034c000b696d706c56657273696f6e71007e000378707702000078fe010000
bytes↗
fe010000aced00057372001d7765626c6f6769632e726a766d2e436c6173735461626c65456e7472792f52658157f4f9ed0c000078707200217765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e50656572496e666f585474f39bc908f10200074900056d616a6f724900056d696e6f7249000b706174636855706461746549000c726f6c6c696e67506174636849000b736572766963655061636b5a000e74656d706f7261727950617463685b00087061636b616765737400275b4c7765626c6f6769632f636f6d6d6f6e2f696e7465726e616c2f5061636b616765496e666f3b787200247765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e56657273696f6e496e666f972245516452463e0200035b00087061636b6167657371007e00034c000e72656c6561736556657273696f6e7400124c6a6176612f6c616e672f537472696e673b5b001276657273696f6e496e666f417342797465737400025b42787200247765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e5061636b616765496e666fe6f723e7b8ae1ec90200094900056d616a6f724900056d696e6f7249000b706174636855706461746549000c726f6c6c696e67506174636849000b736572766963655061636b5a000e74656d706f7261727950617463684c0009696d706c5469746c6571007e00054c000a696d706c56656e646f7271007e00054c000b696d706c56657273696f6e71007e000578707702000078fe00fffe010000aced0005737200137765626c6f6769632e726a766d2e4a564d4944dc49c23ede121e2a0c00007870774621000000000000000000093132372e302e312e31000b75732d6c2d627265656e73a53caff10000000700001b59ffffffffffffffffffffffffffffffffffffffffffffffff0078fe010000aced0005737200137765626c6f6769632e726a766d2e4a564d4944dc49c23ede121e2a0c00007870771d018140128134bf427600093132372e302e312e31a53caff1000000000078
- →Exploit targets the WebLogic T3 protocol interface; detect by monitoring for T3 handshake strings followed by large serialized object payloads containing 'aced0005' (Java serialization magic bytes) on port 7001. ↗
- →Shodan/FOFA queries can identify exposed WebLogic instances: search for product:'oracle weblogic' or title='oracle peoplesoft sign-in' to find potentially vulnerable targets. ↗
- →DNS-based out-of-band interaction (OAST) is used to confirm exploitation; monitor for unexpected DNS lookups originating from WebLogic server processes. ↗
- →The exploit payload size prefix '00000460' (hex) in the T3 stream can serve as a network signature element for the MarshalledObject deserialization exploit. ↗
- ·The nuclei template targets two hosts per check: the generic hostname and hostname:7001 explicitly, meaning detection only fires if port 7001 is reachable or the default port resolves to T3. ↗
- ·Confirmation of exploitation relies on out-of-band DNS interaction (interactsh); environments blocking outbound DNS from the WebLogic server will not produce a match on the 'dns' word matcher. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33g3-59w3-q9cj: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2016-3586 [CRITICAL] GHSA-33g3-59w3-q9cj: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510.
GHSA
GHSA-88m7-cp4v-hhw3: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2016-3510 [CRITICAL] GHSA-88m7-cp4v-hhw3: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586.
No detection rules found.
Metasploit
Oracle Weblogic Server Deserialization RCE - MarshalledObject
metasploit
Oracle Weblogic Server Deserialization RCE - MarshalledObject
Oracle Weblogic Server Deserialization RCE - MarshalledObject
An unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object (weblogic.corba.utils.MarshalledObject) to the interface to execute code on vulnerable hosts.
Nuclei
Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
nuclei·CVSS 9.8
CVE-2016-3510 [CRITICAL] Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586.
Template:
id: CVE-2016-3510
info:
name: Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
author: iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Cor
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20·CVSS 9.8
[CRITICAL] Hunting for Web Shells
Blog /
Subscribe
# Hunting for Web Shells
Jacob Baines
December 20, 2016
10 Min Read
Web shells are nothing new, but their use continues to plague security professionals and their customers. With low anti-virus detection rates and few good tools to aid in discovery, how can you fight back?
### A breach has occurred
On November 25th, 900 San Francisco Municipal Transportation Agency (SFMTA) computers were infected by a ransomware variant known as HDDCryptor. The ransom demand was 100 bitcoins (approximately $73,000). Due to the attack the SFMTA was temporarily unable to collect an estimated $50,000 in fares.
"You Hacked, ALL Data Encrypted, Contact For Key([email protected])ID:601, Enter Key:"
The immediate question is: “How did this happen?” In a press release, the SFMTA stated th
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20
Hunting for Web Shells
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://packetstormsecurity.com/files/152324/Oracle-Weblogic-Server-Deserialization-MarshalledObject-Remote-Code-Execution.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1036373https://www.tenable.com/security/research/tra-2016-21http://packetstormsecurity.com/files/152324/Oracle-Weblogic-Server-Deserialization-MarshalledObject-Remote-Code-Execution.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1036373https://www.tenable.com/security/research/tra-2016-21
2016-07-21
Published