CVE-2015-4852 PUBLISHED KEV

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

EPSS 92.87% · 99.8th percentile

Risk Scores

EPSS Score
92.87%
99.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopenjdk-88u462-ga~us1-0ubuntu2~16.04.2, 8u482-ga~us1-0ubuntu1~16.04, 8u472-ga-1~16.04
Ubuntu:Pro:18.04:LTSopenjdk-88u171-b11-0ubuntu0.18.04.1, 0, 8u144-b01-2
Ubuntu:Pro:14.04:LTSlibcommons-collections3-java3.2.1-6, 3.2.1-5build1, 0
Ubuntu:Pro:20.04:LTSopenjdk-88u232-b09-1, 8u242-b04-1, 8u242-b08-0ubuntu3
Ubuntu:24.04:LTSopenjdk-88u482-ga~us1-0ubuntu1~24.04, 8u472-ga-1~24.04, 8u462-ga~us1-0ubuntu2~24.04.2
Ubuntu:22.04:LTSopenjdk-88u482-ga~us1-0ubuntu1~22.04, 8u452-ga~us1-0ubuntu1~22.04, 8u302-b08-0ubuntu2

Timeline

References

Open in Interactive Console →