Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
HighCISA KEVExploited in the wildPublic exploit

Oracle WebLogic Server Web Services XMLDecoder Deserialization RCE

IdentifiersCVE-2017-3506CWE-502

CVE-2017-3506 affects the Web Services component of Oracle WebLogic Server in supported versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, and 12.2.1.2. The provided content states that the flaw is exploitable by an unauthenticated attacker over HTTP and is widely described in reporting as a deserialization issue enabling remote OS command execution via a specifically crafted XML document embedded in an HTTP request. The vulnerable attack surface is the WebLogic Web Services stack, and the issue has been characterized in the supplied material as an XMLDecoder/deserialization-style RCE primitive that can be used to execute arbitrary commands on the target host.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow compromise of Oracle WebLogic Server by an unauthenticated remote attacker. According to the provided Oracle description, impact includes unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server-accessible data. The supporting reporting further indicates attackers have used the flaw for remote OS command execution to deploy follow-on payloads such as cryptocurrency miners, enabling full post-exploitation activity consistent with server-side command execution.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict network exposure to WebLogic administrative and Web Services endpoints, especially HTTP-accessible public-facing interfaces. Limit access through segmentation, reverse proxies, ACLs, or WAF controls capable of detecting/blocking crafted XML SOAP payloads associated with this flaw. Monitor for suspicious HTTP requests containing crafted XML, unexpected child processes spawned by WebLogic, and outbound retrieval of secondary payloads. Given observed exploitation in the wild, assume exposed unpatched systems are at elevated risk and perform threat hunting for post-compromise activity.

Remediation

Patch, then assume compromise.

Apply Oracle’s security updates for CVE-2017-3506 and upgrade affected Oracle WebLogic Server installations to vendor-fixed versions. Because the content identifies affected releases as 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, and 12.2.1.2, organizations should verify patch status for those branches and follow Oracle Critical Patch Update guidance. Internet-exposed WebLogic instances should be prioritized for remediation.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.

VALID 0 / 2 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleWeblogic Serverapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.