CVE-2015-4852

Priority
Description
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0,
12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary
commands via a crafted serialized Java object in T3 protocol traffic to TCP
port 7001, related to
oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE:
the scope of this CVE is limited to the WebLogic Server product.
Notes
 sbeattie> according to infoq article and digging through openjdk
  source, there is at least an embedded copy of xalan xslt in openjdk
  which is also vulnerable, though it may be just an example of a
  target class to overwrite via desrialization.
 sbeattie> same as above for libxalan2-java
 mdeslaur> This CVE was originally assigned to Oracle WebLogic, and then
 mdeslaur> was subsequently used by IBM Websphere. It has been proposed to
 mdeslaur> use it for commons-collections. See:
 mdeslaur> http://www.openwall.com/lists/oss-security/2015/11/15/1
 mdeslaur> Red Hat has assigned CVE-2015-7501 to the issue in
 mdeslaur> JBoss Middleware Suite
 mdeslaur> as of 2018-09-19, no indication that this is being fixed in
 mdeslaur> openjdk, or if it is an issue at all. Marking as ignored.
Package
Upstream:released (3.2.2)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (3.2.2-1)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (3.2.2-1)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (3.2.2-1)
Ubuntu 19.04 (Disco Dingo):not-affected (3.2.2-1)
Patches:
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1713307
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1713537
Package
Upstream:not-affected (code not present)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (code not present)
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (code not present)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (code not present)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (code not present)
Ubuntu 19.04 (Disco Dingo):not-affected (code not present)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):ignored
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Ubuntu 19.04 (Disco Dingo):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):ignored
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Ubuntu 19.04 (Disco Dingo):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):ignored
Ubuntu 18.04 LTS (Bionic Beaver):ignored
Ubuntu 18.10 (Cosmic Cuttlefish):ignored
Ubuntu 19.04 (Disco Dingo):DNE
More Information

Updated: 2019-04-17 17:14:21 UTC (commit d1c3cdcbf011c1ed42c17f725c3014a501d0451a)