Denial of service in Oracle WebLogic Server - CVE-2017-10271
Published: December 28, 2017 / Updated: June 17, 2021
Vulnerability identifier: #VU9815
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10271
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to a flaw in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). A remote attacker with network access via HTTP can compromise Oracle WebLogic Server.
The weakness exists due to a flaw in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). A remote attacker with network access via HTTP can compromise Oracle WebLogic Server.
Affected software
Oracle WebLogic Server
How to mitigate CVE-2017-10271
Install update from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #6322 - Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #6324 - Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution (June 17, 2021)
- Exploit #6327 - Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution (June 17, 2021)
- Exploit #5286 - cve-exploits () (April 12, 2021)
- Exploit #2313 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #2283 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #1963 - CVE-2017-10271 (WebLogic Exploit) (March 18, 2020)
- Exploit #1997 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #2048 - CVE-2017-10271 (Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)) (March 18, 2020)
- Exploit #2141 - weblogic_wls_wsat_rce (forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12. (March 18, 2020)
- Exploit #2186 - CVE-2019-2725 (WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit ) (March 18, 2020)
- Exploit #1920 - Oracle-WebLogic-WLS-WSAT (Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)) (March 18, 2020)
- Exploit #174 - CVE-2017-10271 (Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)) (March 18, 2020)
- Exploit #175 - CVE-2017-10271 (Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability al (March 18, 2020)
- Exploit #1541 - Oracle Weblogic Server Deserialization RCE - AsyncResponseService (March 18, 2020)
- Exploit #1768 - Oracle WebLogic wls-wsat Component Deserialization RCE (March 18, 2020)