CVE-2015-4852
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
- Published
- Nov 18, 2015
- Updated
- Oct 21, 2025
- Assigning CNA
- oracle
- Evidence observed
- Jul 20, 2016
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
Sources
7- CVE-2015-4852Exploit
Python exploit script for CVE-2015-4852 (WebLogic RCE) using ysoserial payloads to achieve remote shell access on vulnerable WebLogic servers.
- serialatorExploit
Python script to exploit CVE-2015-4852.
CVE-2015-4852 Oracle WebLogic Scanner
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.