The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 15, 2015 |
| Oracle Weblogic | — | Apply hotfix 22248372 for Oracle WebLogic Server versions between 12.1.2.0.0 - 12.1.2.0.7.Apply hotfix 22248372 for Oracle WebLogic Server versions between 10.3.6.0.0 - 10.3.6.0.12.Apply hotfix 22248372 for Oracle WebLogic Server versions between 12.1.3.0.0 - 12.1.3.0.5.Apply hotfix 22248372 for Oracle WebLogic Server versions between 12.2.1.0.0 - 12.2.1.0.0. | Apr 3, 2018 | Nov 18, 2015 |
| Suse | — | Upgrade apache-commons-beanutils | Feb 4, 2022 | Nov 18, 2015 |
| Ubuntu | — | Upgrade libcommons-collections3-java (Ubuntu Pro) | Aug 1, 2024 | Nov 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub