CVE-2015-4852

CRITICAL KEV

Oracle Virtual Desktop Infrastructure - Insecure Deserialization

Title source: rule

Description

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Exploits (11)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/46628
exploitdb WORKING POC
by SlidingWindow · pythonremotejava
https://www.exploit-db.com/exploits/42806
exploitdb WORKING POC
by Nikhil Sreekumar · bashremotemultiple
https://www.exploit-db.com/exploits/44552
nomisec WORKING POC 31 stars
by roo7break · remote
https://github.com/roo7break/serialator
nomisec WORKING POC 17 stars
by zhzhdoai · remote
https://github.com/zhzhdoai/Weblogic_Vuln
github WORKING POC 6 stars
by Y5neKO · pythonpoc
https://github.com/Y5neKO/ExpAndPoc_Collection/tree/main/CVE-2015-4852
nomisec SCANNER 2 stars
by AndersonSingh · poc
https://github.com/AndersonSingh/serialization-vulnerability-scanner
nomisec WORKING POC 1 stars
by nex1less · remote
https://github.com/nex1less/CVE-2015-4852
vulncheck_xdb WORKING POC
remote
https://gitlab.com/milo2012/cve-2015-4852
vulncheck_xdb WORKING POC
remote
https://github.com/minhangxiaohui/Weblogic_direct_T3_Rces
metasploit WORKING POC EXCELLENT
by Andres Rodriguez · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_rawobject.rb

References (16)

Scores

CVSS v3 9.8
EPSS 0.9295
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-10-20
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2015-4869
CWE
CWE-502
Status published
Products (6)
oracle/storagetek_tape_analytics_sw_tool 2.3
oracle/virtual_desktop_infrastructure < 3.5.2
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.2.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.0.0
Published Nov 18, 2015
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026