Skip to content
COOEY

EXPOSURES › CVE-2017-3506

CVE-2017-3506

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-06-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-3506 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests.

This OS command injection flaw allowed attackers to execute arbitrary code via crafted HTTP requests, posing a severe risk to DIB organizations relying on Oracle Fusion Middleware. The vulnerability was actively exploited in the wild before patching, requiring immediate network segmentation and patching to prevent unauthorized access to enterprise systems.

Shame score — The vulnerability was actively exploited in the wild for years, indicating a failure to patch and maintain security posture despite known risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized