CVE Vulnerabilities

CVE-2015-4852

Deserialization of Untrusted Data

Published: Nov 18, 2015 | Modified: Oct 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

Weakness

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Software

NameVendorStart VersionEnd Version
Virtual_desktop_infrastructureOracle*3.5.2 (including)
Libcommons-collections3-javaUbuntuesm-infra-legacy/trusty*
Libcommons-collections3-javaUbuntuprecise*
Libcommons-collections3-javaUbuntutrusty*
Libcommons-collections3-javaUbuntutrusty/esm*
Libcommons-collections3-javaUbuntuupstream*
Libcommons-collections3-javaUbuntuvivid*
Libcommons-collections3-javaUbuntuwily*
Libcommons-collections4-javaUbuntutrusty*
Libcommons-collections4-javaUbuntuupstream*
Libcommons-collections4-javaUbuntuvivid*
Libcommons-collections4-javaUbuntuwily*
Libxalan2-javaUbuntuartful*
Libxalan2-javaUbuntuprecise*
Libxalan2-javaUbuntuvivid*
Libxalan2-javaUbuntuwily*
Libxalan2-javaUbuntuyakkety*
Libxalan2-javaUbuntuzesty*
Openjdk-6Ubuntuprecise*
Openjdk-6Ubuntutrusty*
Openjdk-6Ubuntuvivid*
Openjdk-6Ubuntuwily*
Openjdk-7Ubuntuprecise*
Openjdk-7Ubuntutrusty*
Openjdk-7Ubuntuvivid*
Openjdk-7Ubuntuwily*
Openjdk-8Ubuntuartful*
Openjdk-8Ubuntubionic*
Openjdk-8Ubuntucosmic*
Openjdk-8Ubuntudevel*
Openjdk-8Ubuntudisco*
Openjdk-8Ubuntueoan*
Openjdk-8Ubuntuesm-apps/bionic*
Openjdk-8Ubuntuesm-apps/focal*
Openjdk-8Ubuntuesm-apps/jammy*
Openjdk-8Ubuntuesm-apps/noble*
Openjdk-8Ubuntuesm-infra/xenial*
Openjdk-8Ubuntufocal*
Openjdk-8Ubuntugroovy*
Openjdk-8Ubuntuhirsute*
Openjdk-8Ubuntuimpish*
Openjdk-8Ubuntujammy*
Openjdk-8Ubuntukinetic*
Openjdk-8Ubuntulunar*
Openjdk-8Ubuntumantic*
Openjdk-8Ubuntunoble*
Openjdk-8Ubuntuoracular*
Openjdk-8Ubuntuvivid*
Openjdk-8Ubuntuwily*
Openjdk-8Ubuntuxenial*
Openjdk-8Ubuntuyakkety*
Openjdk-8Ubuntuzesty*

Potential Mitigations

  • Make fields transient to protect them from deserialization.
  • An attempt to serialize and then deserialize a class containing transient fields will result in NULLs where the transient data should be. This is an excellent way to prevent time, environment-based, or sensitive variables from being carried over and used improperly.

References