S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-3506 Scanner

CVE-2017-3506 scanner - OS Command Injection vulnerability in Oracle WebLogic Server

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-3506
7.4
CVSShigh
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
10.3.6.0
weblogic_serverby oracle
10.3.6.0.0
weblogic_serverby oracle
10.3.6.0.0
weblogic_serverby oracle
10.3.6.0.0
Updated Aug 22, 2026View on NVD →
Detail

Oracle WebLogic Server is a Java Enterprise Edition-based application server used by businesses for building and deploying enterprise applications. It is a highly scalable and reliable server that provides a secure and efficient platform for developing and hosting applications.

CVE-2017-3506 is a vulnerability that was recently detected in Oracle WebLogic Server. It is a difficult-to-exploit vulnerability that can be used by an unauthenticated attacker to gain unauthorized access to critical data or modify it. Any user having network access via HTTP can compromise Oracle WebLogic Server, especially if they are using one of the supported versions (10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, and 12.2.1.2).

When exploited, this vulnerability can lead to unauthorized access to critical data, unauthorized creation, deletion, or modification of data, and complete access to all Oracle WebLogic Server-accessible data. As a result, it can cause significant damage to businesses, such as reputational damage, loss of sensitive data, and violation of compliance regulations.

In conclusion, businesses need to be aware of the CVE-2017-3506 vulnerability and take necessary steps to protect their assets from it. With the advanced features of the s4e.io platform, it is effortless and quick to identify vulnerabilities in digital assets. By using this platform, businesses can stay ahead of the game and minimize the risk of cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses can take the following precautions:

  • Apply the security patch released by Oracle.
  • Avoid exposing the Oracle WebLogic Server to untrusted networks.
  • Monitor network traffic and identify the signs of any intrusion or unauthorised access.
  • Use a Web Application Firewall (WAF) to filter out malicious traffic.
  • Conduct a vulnerability assessment and penetration testing to identify and remediate any vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.