CVE-2017-10271

HIGH KEV RANSOMWARE NUCLEI LAB

Oracle WebLogic wls-wsat Component Deserialization RCE

Title source: metasploit

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Exploits (37)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/43924
exploitdb WORKING POC VERIFIED
by Kevin Kirsche · pythonremotemultiple
https://www.exploit-db.com/exploits/43458
exploitdb WORKING POC
by 1337g · pythonremotemultiple
https://www.exploit-db.com/exploits/43392
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2017-10271.md
nomisec WORKING POC 506 stars
by shack2 · poc
https://github.com/shack2/javaserializetools
nomisec WORKING POC 143 stars
by c0mmand3rOpSec · remote
https://github.com/c0mmand3rOpSec/CVE-2017-10271
nomisec WORKING POC 128 stars
by kkirsche · remote
https://github.com/kkirsche/CVE-2017-10271
nomisec SUSPICIOUS 114 stars
by 7kbstorm · poc
https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814
nomisec WORKING POC 105 stars
by SkyBlueEternal · remote
https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961
nomisec WORKING POC 39 stars
by 1337g · remote
https://github.com/1337g/CVE-2017-10271
nomisec WORKING POC 33 stars
by Cymmetria · poc
https://github.com/Cymmetria/weblogic_honeypot
nomisec WORKING POC 29 stars
by Luffin · remote
https://github.com/Luffin/CVE-2017-10271
nomisec WORKING POC 22 stars
by s3xy · remote
https://github.com/s3xy/CVE-2017-10271
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2017-10271.md
nomisec SCANNER 9 stars
by ETOCheney · remote
https://github.com/ETOCheney/JavaDeserialization
nomisec WORKING POC 7 stars
by SuperHacker-liuan · poc
https://github.com/SuperHacker-liuan/cve-2017-10271-poc
nomisec WORKING POC 5 stars
by pssss · remote
https://github.com/pssss/CVE-2017-10271
nomisec WORKING POC 4 stars
by kbsec · remote
https://github.com/kbsec/Weblogic_Wsat_RCE
nomisec WORKING POC 3 stars
by pizza-power · remote
https://github.com/pizza-power/weblogic-CVE-2019-2729-POC
nomisec WORKING POC 3 stars
by cjjduck · remote
https://github.com/cjjduck/weblogic_wls_wsat_rce
nomisec WORKING POC 3 stars
by ZH3FENG · poc
https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271
nomisec WORKING POC 2 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2017-10271
nomisec SUSPICIOUS 2 stars
by ianxtianxt · poc
https://github.com/ianxtianxt/-CVE-2017-10271-
nomisec WORKING POC 1 stars
by XHSecurity · remote
https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271
nomisec SUSPICIOUS 1 stars
by Yuusuke4 · poc
https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814
nomisec WORKING POC 1 stars
by lonehand · poc
https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master
nomisec WORKING POC 1 stars
by JackyTsuuuy · remote
https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp
nomisec WORKING POC
by seoyoung-kang · remote
https://github.com/seoyoung-kang/CVE-2017-10271
nomisec STUB
by cved-sources · poc
https://github.com/cved-sources/cve-2017-10271
nomisec WORKING POC
by testwc · remote
https://github.com/testwc/CVE-2017-10271
nomisec WORKING POC
by r4b3rt · remote-auth
https://github.com/r4b3rt/CVE-2017-10271
nomisec WRITEUP
by peterpeter228 · poc
https://github.com/peterpeter228/Oracle-WebLogic-CVE-2017-10271
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/oracle_weblogic_wsat_deserialization_rce.rb

Nuclei Templates (1)

Oracle WebLogic Server - Remote Command Execution
HIGHby dr_set,ImNightmaree,true13
Shodan: http.title:"oracle peoplesoft sign-in" || product:"oracle weblogic"
FOFA: title="oracle peoplesoft sign-in"

Scores

CVSS v3 7.5
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull zhiqzhao/ubuntu_weblogic1036_domain
docker pull vulhub/weblogic:10.3.6.0-2017
+28 more repos

Details

CISA KEV 2022-02-10
VulnCheck KEV 2017-01-17
InTheWild.io 2018-02-15
ENISA EUVD EUVD-2017-1918
Ransomware Use Confirmed
CWE
CWE-306
Status published
Products (8)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.1.0
oracle/weblogic_server 12.2.1.2.0
Oracle Corporation/WebLogic Server 10.3.6.0.0
Oracle Corporation/WebLogic Server 12.1.3.0.0
Oracle Corporation/WebLogic Server 12.2.1.1.0
Oracle Corporation/WebLogic Server 12.2.1.2.0
Published Oct 19, 2017
KEV Added Feb 10, 2022
Tracked Since Feb 18, 2026