February 10, 2022 · Applied Cybernetics Group
CVE-2017-10271 — Oracle WebLogic Server
known ransomware use
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
- Added to KEV
2022-02-10- Federal due date
2022-08-10- Vendor
- Oracle
- Product
- WebLogic Server
- EPSS
- 100.0th percentile (score 1.000, as of
2026-09-16) - NVD CVSS v3.1
- 7.5 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2017-10271
CISA short description
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).