🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVE
CVE-2017-10271
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Attack Vector
Network
Privileges Req.
None
User Interaction
None
weblogic server
Updated Sep 18, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
CVE history: weblogic server
Predict next CVE date with AIMonitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →