CVE-2015-4852
KEVCRITICAL 9.8EPSS 96.0%
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 96.03% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Published
- 2015-11-18
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/152268/Oracle-Weblogic-Server-Deserialization-Remote…
- nex1less/CVE-2015-48521★ · 2020-11-16
- roo7break/serialator31★ · 2016-07-20
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/46628
- https://www.exploit-db.com/exploits/44552
- https://www.exploit-db.com/exploits/42806