Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-4852
Description:The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
Test IDs: 1.3.6.1.4.1.25623.1.1.12.2024.6936.1   1.3.6.1.4.1.25623.1.0.806622   1.3.6.1.4.1.25623.1.0.105829  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-4852
BugTraq ID: 77539
http://www.securityfocus.com/bid/77539
https://www.exploit-db.com/exploits/42806/
https://www.exploit-db.com/exploits/46628/
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
https://github.com/foxglovesec/JavaUnserializeExploits/blob/master/weblogic.py
http://www.openwall.com/lists/oss-security/2015/11/17/19
http://www.securitytracker.com/id/1038292




© 1998-2025 E-Soft Inc. All rights reserved.