CVE-2017-10271

Analyzed
Published: 19 Oct 2017, 17:00
Last modified:13 Aug 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
60/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
99.99% CRITICAL
100% probability +5.55%
KEV
Listed
CISA • ENISA
2 listings
Ransomware
Known Use
Public exploits
5 found
Dark Web
Not detected

Timeline

19 Oct 2017, 17:00
Published
Vulnerability first disclosed
10 Feb 2022, 00:00
Added to CISA KEV
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
10 Aug 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
10 Aug 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
13 Aug 2026, 03:55
Last Modified
Vulnerability information updated

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 99.99% Percentile: 100%

Techniques & Countermeasures

  • CWE-306Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Affected Systems

  • oracle corporationweblogic server

    10.3.6.0.0 | 12.1.3.0.0 | 12.2.1.1.0 | 12.2.1.2.0

  • oracleweblogic_server

    10.3.6.0.0 | 12.1.3.0.0 | 12.2.1.1.0 | 12.2.1.2.0

References (7)