Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Oracle Corporation | WebLogic Server | 10.3.6.0.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2017-10271 WEBLOGIC RCE (TESTED) | https://github.com/1337g/CVE-2017-10271 | POC Details |
| 2 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. | https://github.com/s3xy/CVE-2017-10271 | POC Details |
| 3 | Simplified PoC for Weblogic-CVE-2017-10271 | https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271 | POC Details |
| 4 | WebLogic Exploit | https://github.com/c0mmand3rOpSec/CVE-2017-10271 | POC Details |
| 5 | CVE-2017-10271 POC | https://github.com/Luffin/CVE-2017-10271 | POC Details |
| 6 | forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.Modified by hanc00l | https://github.com/cjjduck/weblogic_wls_wsat_rce | POC Details |
| 7 | Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271) | https://github.com/kkirsche/CVE-2017-10271 | POC Details |
| 8 | CVE-2017-10271 Weblogic 漏洞验证Poc及补丁 | https://github.com/pssss/CVE-2017-10271 | POC Details |
| 9 | cve-2017-10271 POC | https://github.com/SuperHacker-liuan/cve-2017-10271-poc | POC Details |
| 10 | WebLogic wls-wsat RCE CVE-2017-10271 | https://github.com/peterpeter228/Oracle-WebLogic-CVE-2017-10271 | POC Details |
| 11 | WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability. | https://github.com/Cymmetria/weblogic_honeypot | POC Details |
| 12 | cve-2017-10271 | https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp | POC Details |
| 13 | Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271) | https://github.com/R0B1NL1N/Oracle-WebLogic-WLS-WSAT | POC Details |
| 14 | None | https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master | POC Details |
| 15 | Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。 | https://github.com/shack2/javaserializetools | POC Details |
| 16 | 针对类似CVE-2017-10271漏洞的一个java反序列化漏洞扫描器 | https://github.com/ETOCheney/JavaDeserialization | POC Details |
| 17 | Weblogic(CVE-2017-10271) | https://github.com/r4b3rt/CVE-2017-10271 | POC Details |
| 18 | cve-2017-10271 | https://github.com/cved-sources/cve-2017-10271 | POC Details |
| 19 | Oracle-WebLogic-CVE-2017-10271 | https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271 | POC Details |
| 20 | POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code. | https://github.com/kbsec/Weblogic_Wsat_RCE | POC Details |
| 21 | CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC | https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961 | POC Details |
| 22 | WebLogic CNVD-C-2019_48814 CVE-2017-10271 | https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814 | POC Details |
| 23 | WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm | https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814 | POC Details |
| 24 | (CVE-2017-10271)Java反序列化漏洞 | https://github.com/ianxtianxt/-CVE-2017-10271- | POC Details |
| 25 | CVE-2017-10271 | https://github.com/testwc/CVE-2017-10271 | POC Details |
| 26 | CVE-2017-10271 | https://github.com/Al1ex/CVE-2017-10271 | POC Details |
| 27 | python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others | https://github.com/pizza-power/weblogic-CVE-2019-2729-POC | POC Details |
| 28 | WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm | https://github.com/KKsdall/7kbstormq | POC Details |
| 29 | The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent - WLS Security) is susceptible to remote command execution. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-10271.yaml | POC Details |
| 30 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Weblogic%20%2010.3.6%20wls-wsat%20XMLDecoder%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%20CVE-2017-10271.md | POC Details |
| 31 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Weblogic%20XMLDecoder%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2017-10271.md | POC Details |
| 32 | Weblogic wls-wsat XMLDecoder deserialization RCE CVE-2019-2725 + org.slf4j.ext.EventData | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/weblogic-cve-2019-2725.yml | POC Details |
| 33 | Weblogic wls-wsat XMLDecoder deserialization RCE CVE-2017-10271 | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/weblogic-cve-2017-10271.yml | POC Details |
| 34 | https://github.com/vulhub/vulhub/blob/master/weblogic/CVE-2017-10271/README.md | POC Details | |
| 35 | Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271) | https://github.com/seoyoung-kang/CVE-2017-10271 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-10373 | Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞 | |
| CVE-2017-10360 | Oracle Fusion Middleware Oracle WebCenter Content组件安全漏洞 | |
| CVE-2017-10361 | Oracle Hospitality Applications Oracle Hospitality Cruise Shipboard Property Management Sy | |
| CVE-2017-10362 | Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞 | |
| CVE-2017-10363 | Oracle Financial Services Applications Oracle FLEXCUBE Universal Banking组件安全漏洞 | |
| CVE-2017-10365 | Oracle MySQL Server组件安全漏洞 | |
| CVE-2017-10366 | Oracle PeopleSoft Products PeopleSoft Enterprise PT PeopleTools组件安全漏洞 | |
| CVE-2017-10367 | Oracle Hospitality Applications Oracle Hospitality Simphony组件安全漏洞 | |
| CVE-2017-10368 | Oracle PeopleSoft Products PeopleSoft Enterprise SCM eProcurement组件安全漏洞 | |
| CVE-2017-10369 | Oracle Fusion Middleware Oracle Virtual Directory组件安全漏洞 | |
| CVE-2017-10370 | Oracle Hospitality Applications Oracle Hospitality Guest Access组件安全漏洞 | |
| CVE-2017-10372 | Oracle Hospitality Applications Oracle Hospitality Guest Access组件安全漏洞 | |
| CVE-2017-10382 | Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞 | |
| CVE-2017-10387 | Oracle E-Business Suite Oracle CRM Technical Foundation组件安全漏洞 | |
| CVE-2017-10386 | Oracle Java SE Java Advanced Management Console组件安全漏洞 | |
| CVE-2017-10385 | Oracle Fusion Middleware Oracle GlassFish Server组件安全漏洞 | |
| CVE-2017-10384 | Oracle MySQL Server组件安全漏洞 | |
| CVE-2017-10383 | Oracle Hospitality Applications Oracle Hospitality Guest Access组件安全漏洞 | |
| CVE-2017-10380 | Oracle Java SE Java Advanced Management Console组件安全漏洞 | |
| CVE-2017-10375 | Oracle Hospitality Applications Oracle Hospitality Guest Access组件安全漏洞 |
Showing top 20 of 178 CVEs. View all on vendor page → →
No comments yet