CVE-2015-4852
CRITICAL KEVOracle Virtual Desktop Infrastructure - Insecure Deserialization
Title source: ruleDescription
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
Exploits (11)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/46628
exploitdb
WORKING POC
by Nikhil Sreekumar · bashremotemultiple
https://www.exploit-db.com/exploits/44552
github
WORKING POC
6 stars
by Y5neKO · pythonpoc
https://github.com/Y5neKO/ExpAndPoc_Collection/tree/main/CVE-2015-4852
nomisec
SCANNER
2 stars
by AndersonSingh · poc
https://github.com/AndersonSingh/serialization-vulnerability-scanner
metasploit
WORKING POC
EXCELLENT
by Andres Rodriguez · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_rawobject.rb
References (16)
[Patch, Vendor Advisory] http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
[Patch, Vendor Advisory] http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
[Patch, Vendor Advisory] http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Scores
CVSS v3
9.8
EPSS
0.9295
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-10-20
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2015-4869
CWE
CWE-502
Status
published
Products (6)
oracle/storagetek_tape_analytics_sw_tool
2.3
oracle/virtual_desktop_infrastructure
< 3.5.2
oracle/weblogic_server
10.3.6.0.0
oracle/weblogic_server
12.1.2.0.0
oracle/weblogic_server
12.1.3.0.0
oracle/weblogic_server
12.2.1.0.0
Published
Nov 18, 2015
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026