CVE-2017-3506 Details
Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
An OS command injection vulnerability has been identified in Oracle WebLogic Server, part of the Oracle Fusion Middleware suite, specifically within the Web Services component. This vulnerability affects versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, and 12.2.1.2. The vulnerability allows an unauthenticated attacker with network access via HTTP to execute arbitrary commands on the server. Exploitation of this vulnerability could lead to unauthorized creation, deletion, or modification of critical data, or all data accessible to Oracle WebLogic Server.
Users are advised to apply the latest patches provided by Oracle. Instructions for patching can be found in the Oracle WebLogic Server Patch Advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 28, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-3506 | CISA-ADP | US Government Resource |
| http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html | CVE | PatchVendor Advisory |
| http://www.securityfocus.com/bid/97884 | CVE | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038296 | CVE | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html | [email protected] | PatchVendor Advisory |
| http://www.securityfocus.com/bid/97884 | [email protected] | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038296 | [email protected] | Broken LinkThird Party AdvisoryVDB Entry |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Oracle WebLogic Server OS Command Injection Vulnerability | Jun 3, 2024 | Jun 24, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| oracle weblogic server | 10.3.6.0.0 12.1.3.0.0 12.2.1.0.0 12.2.1.1.0 12.2.1.2.0 |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 14, 2024 | Modified Analysis | [email protected] |
| Jul 3, 2024 | CVE Modified | CISA-ADP |
| Jun 7, 2024 | Modified Analysis | [email protected] |
| Jun 4, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| May 1, 2017 | Initial Analysis | [email protected] |
| Apr 26, 2017 | CVE Modified | [email protected] |