CVE-2017-10271

HIGH7.5Published on October 19, 2017

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Feb 10, 2022
  • US federal agencies must remediate it by Aug 10, 2022 (BOD 22-01)
  • Attacked 276 days before the vulnerability was made public
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply updates per vendor instructions.

Source: CISA KEV · Aug 24, 2026 Aug 23, 2026 Aug 22, 2026 Aug 20, 2026 Aug 19, 2026 Aug 18, 2026

CVSS score7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness type (CWE)CWE-306
Vendorsoracle

Affected products

VendorsProdottoVersioni
oracleweblogic server10.3.6.0.0

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database