VDB

CVE-2015-4852

CVE-2015-4852 PUBLISHED KEV

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

EPSS 92.95% · 99.8th percentile

Risk Scores

EPSS Score
92.95%
99.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopenjdk-88u372-ga~us1-0ubuntu1~16.04, 8u312-b07-0ubuntu1~16.04, 8u282-b08-0ubuntu1~16.04
Ubuntu:Pro:18.04:LTSopenjdk-88u382-ga-1~18.04.1, 0, 8u144-b01-2
Ubuntu:Pro:14.04:LTSlibcommons-collections3-java0, 3.2.1-5build1, 3.2.1-6
Ubuntu:Pro:20.04:LTSopenjdk-88u392-ga-1~20.04, 8u382-ga-1~20.04.1, 8u362-ga-0ubuntu1~20.04.1
Ubuntu:24.04:LTSopenjdk-88u402-ga-2, 8u402-ga-2ubuntu7, 8u402-ga-8build1
Ubuntu:22.04:LTSopenjdk-80, *, *

Timeline

  • Nov 18, 2015 CVE Published
  • Sep 28, 2017 PoC Published
  • Apr 29, 2018 PoC Published
  • Nov 3, 2021 CISA KEV Added
  • Feb 4, 2022 EPSS Score
  • Feb 15, 2022 PoC Published
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›