CVE-2017-3506: Oracle WebLogic Server OS Command Injection Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.
Other sources
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3506?
CVE-2017-3506 has been categorized as a critical severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2017-3506?
To fix CVE-2017-3506, you should apply the latest patches provided by Oracle for affected versions of WebLogic Server.
Which versions of Oracle WebLogic Server are affected by CVE-2017-3506?
CVE-2017-3506 affects Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0.
What exploit does CVE-2017-3506 involve?
CVE-2017-3506 involves an OS command injection vulnerability that allows attackers to execute arbitrary code via a malicious HTTP request.
Can CVE-2017-3506 be exploited remotely?
Yes, CVE-2017-3506 can be exploited remotely by sending specially crafted HTTP requests to the vulnerable WebLogic Server.