Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation — WebLogic Server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
7.5
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Published
- Oct 19, 2017
- Modified
- Aug 13, 2026
- Added to KEV
- Feb 10, 2022
- Federal patch due
- Aug 10, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2017-10271, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- 0xn0ne/weblogicScanner★ 2075
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
updated Sep 1, 2026
- shack2/javaserializetools★ 515
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
updated Aug 30, 2026
- c0mmand3rOpSec/CVE-2017-10271★ 143
WebLogic Exploit
updated Jul 24, 2026
- kkirsche/CVE-2017-10271★ 129
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
updated Apr 15, 2026
- 7kbstorm/WebLogic_CNVD_C2019_48814★ 114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
updated Jun 22, 2026
- SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961★ 105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
updated Jul 13, 2026
- 1337g/CVE-2017-10271★ 39
CVE-2017-10271 WEBLOGIC RCE (TESTED)
updated May 15, 2025
- Cymmetria/weblogic_honeypot★ 33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
updated Nov 27, 2025
References
Frequently asked questions
What is CVE-2017-10271?
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
How severe is CVE-2017-10271?
CVE-2017-10271 has a CVSS base score of 7.5 out of 10 (CVSS 3.1).
Is CVE-2017-10271 actively exploited in the wild?
Yes. CVE-2017-10271 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Feb 10, 2022, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2017-10271?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2017-10271?
Yes - a public Nuclei template referencing CVE-2017-10271 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2017-10271?
CVE-2017-10271 is classified under CWE-306 (CWE-306 Missing Authentication for Critical Function).
Cross-checked against
Impactr finds and proves whether CVE-2017-10271 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist