The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcommons-collections3-java", "binary_version": "3.2.1-6ubuntu0.1~esm1" }, { "binary_name": "libcommons-collections3-java-doc", "binary_version": "3.2.1-6ubuntu0.1~esm1" } ] }