CVE-2017-10271
CISA KEVRansomwareAs of 2025-10-22, CVE-2017-10271 is a CVSS 7.5 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 94.4%. Threadlinqs Intelligence tracks 0 threats exploiting it.
Last updated: 2025-10-22
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
NVD-CWE-noinfo, CWE-306
Exploitation status
CISA KEV-listed (known exploited)
References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/101304
- http://www.securitytracker.com/id/1039608
- https://github.com/c0mmand3rOpSec/CVE-2017-10271
- https://www.exploit-db.com/exploits/43458/
- https://www.exploit-db.com/exploits/43924/
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/101304
- http://www.securitytracker.com/id/1039608
- https://github.com/c0mmand3rOpSec/CVE-2017-10271
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.