LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-10271: Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2022
CVSS 7.5 · High⚠ Actively exploited (CISA KEV)Ransomware-linked
7.5
CVSS score
High
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-10271 to its Known Exploited Vulnerabilities catalog on Feb 10, 2022, with a federal patch deadline of Aug 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2017-10271 is a remote code execution vulnerability in Oracle WebLogic Server. An unauthenticated attacker who can reach a vulnerable instance may be able to run arbitrary code on the host, which can lead to full system compromise. CISA notes that this issue has been used by ransomware operators, so organizations still running WebLogic should treat exposure as high priority and confirm their exact status against the vendor advisory.

Because WebLogic often sits behind or near business applications and middleware, successful exploitation can give attackers a foothold into internal networks, data stores, and identity systems. The required action is straightforward: apply the updates Oracle published for this CVE.

How it works

Public detail on the exact weakness class (CWE) is limited in the provided record. At a high level, the vulnerability allows remote code execution on Oracle WebLogic Server. In this product class, such flaws commonly arise when the server deserializes or otherwise processes untrusted input on a network-facing component without sufficient validation, letting an attacker supply data that the runtime interprets as executable instructions or objects.

An attacker who can send crafted requests to an exposed WebLogic endpoint may trigger code execution in the context of the WebLogic process. No exploit mechanics, payloads, or specific protocols beyond the general remote-code-execution description are stated here; defenders should rely on Oracle’s advisory for technical root-cause and affected components rather than assuming a particular attack path.

Am I affected? How to find it in your systems

Oracle WebLogic Server is typically deployed as an application server or middleware tier for Java EE workloads—on-premises data centers, private clouds, and sometimes internet-facing portals or partner integrations. Inventory every host and container that runs WebLogic, including development, test, and DR environments that may be reachable from untrusted networks.

How to remediate

Patch first. Apply the updates Oracle issued for CVE-2017-10271 exactly as described in the vendor advisory and CISA’s required action: “Apply updates per vendor instructions.” After patching, verify the new version/patch level in your inventory and re-scan to confirm the finding is closed.

If you can't patch immediately

If an immediate outage window is impossible, reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities, including those with known ransomware use, frequently precede data theft or encryption. If logs or EDR indicate successful exploitation, follow your incident-response plan: isolate affected hosts, preserve evidence, assess lateral movement, and determine whether sensitive data was accessed. As a quick personal check, individuals can run a free exposure scan of their work email address against known breach datasets to see whether their credentials have appeared in prior incidents, then reset passwords and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · WebLogic Server
WeaknessCWE-306
CVSS base score7.5 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
PublishedOct 19, 2017
Added to CISA KEVFeb 10, 2022
Federal patch deadlineAug 10, 2022
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities