Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 24, 2024

High
CISA KEV

CVE-2017-3506

OracleWebLogic Server

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

Required Action

https://www.oracle.com/security-alerts/cpuapr2017.html; https://nvd.nist.gov/vuln/detail/CVE-2017-3506

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Jun 3, 2024
KEV Added
Jun 3, 2024
Due Date
Jun 24, 2024
Related Articles
0

Vendor

Oracle

WebLogic Server