ZeroHour

CVE-2017-3506

KEVlarge

Unauthenticated OS Command Injection in Oracle WebLogic Server

CISA: Oracle WebLogic Server OS Command Injection Vulnerability

CVSS 3.1
7.4 high
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2017-3506 is an unauthenticated operating system command injection flaw (CWE-78) in the Web Services subcomponent of Oracle WebLogic Server. A remote attacker with network access over HTTP can trigger it, though the flaw is rated difficult to exploit (high attack complexity). Successful exploitation allows the attacker to create, delete, or modify critical data and gain unauthorized access to critical data — potentially all data accessible to WebLogic Server — without authentication, with no availability impact. Organizations running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, or 12.2.1.2 are exposed, especially where the HTTP interface is internet-reachable. The flaw is under active attack: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-03, EPSS is at 96.3%, and the 8220 gang is exploiting it to deliver infostealers and cryptocurrency miners.

What to do: Apply the Oracle Critical Patch Update from April 2017 or later (or upgrade WebLogic Server to a patched, supported release), consistent with CISA's KEV required action to apply vendor mitigations or discontinue use. Until patched, restrict network access to the Web Services HTTP interface. Hunt affected servers for 8220 gang activity — unexpected child processes, cryptomining loads, and infostealer artifacts — since exploitation requires no authentication.

Affected
Oracle WebLogic Server10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, 12.2.1.2
Estimated exposure
largetens of thousands (≈10k–100k) of internet-exposed WebLogic servers; substantially more when internal enterprise deployments are counted — Public internet scan services (e.g., Shodan/Censys) have historically indexed tens of thousands of WebLogic instances reachable over HTTP, and WebLogic's prevalence in large enterprise and government application estates means the total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CISA Known Exploited Vulnerability
Affected
Oracle WebLogic Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
weblogic server
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news