Skip to content
COOEY

EXPOSURES › CVE-2015-4852

CVE-2015-4852

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-4852 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild.

Oracle WebLogic Server contained a deserialization of untrusted data vulnerability allowing remote code execution, which was actively exploited in the wild. DIB organizations must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching, and rigorous vulnerability management to prevent similar exposures.

Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch a known, severe flaw before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Oracle faced severe fallout for CVE-2015-4852, a critical deserialization vulnerability in WebLogic Server allowing remote code execution. The vulnerability was disclosed in 2015 but remained unpatche
cooey ↗ severe-fallout -0.80
Severe criticism for delayed patching and lack of timely response to a critical vulnerability.
"Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution."
securityonline.info ↗ severe-fallout -0.80
Severe criticism; SecurityOnline highlights the ongoing threat landscape and lack of timely vendor patching.
"CVE-2026-8452: Citrix NetScaler Pre-Auth RCE PoC Out"
thecybersecguru.com ↗ severe-fallout -0.70
Negative; The CyberSec Guru discusses a different CVE (2026-8452) but the context implies ongoing issues with vendor vulnerability management.
"CVE-2026-8452: Critical Citrix NetScaler Vulnerability Explained"
xposedornot.com ↗ severe-fallout -0.60
Negative; XposedOrNot lists the vulnerability in breach databases, implying exploitation and lack of timely mitigation.
"Browse 776 breaches across 20 industries."
www.oracle.com ↗ severe-fallout -0.50
Neutral to negative; Oracle's security alert page lacks specific commentary on CVE-2015-4852, reflecting a lack of proactive communication.
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
cvedb.shodan.io ↗ severe-fallout -0.50
Neutral; Shodan's CVEDB API provides data but does not comment on Oracle's handling.
"CVEDB API - Fast Vulnerability Dashboard"
www.cvefind.com ↗ severe-fallout -0.40
Neutral; CVE Find lists the vulnerability but does not provide commentary on Oracle's handling.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized