---
id: CVE-2017-10271
title: >-
  Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
  Middleware (subcomponent: WLS Security)
summary: >-
  Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
  Middleware (subcomponent: WLS Security). Supported versions that are affected
  are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable
  vulnerability …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-306
vendor: oracle
product: weblogic_server
affected:
  - weblogic_server = 10.3.6.0.0
  - weblogic_server = 12.1.3.0.0
  - weblogic_server = 12.2.1.1.0
  - weblogic_server = 12.2.1.2.0
published: '2017-10-19'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-10271'
references:
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: secalert_us@oracle.com
  - url: 'http://www.securityfocus.com/bid/101304'
    label: secalert_us@oracle.com
  - url: 'http://www.securitytracker.com/id/1039608'
    label: secalert_us@oracle.com
  - url: 'https://github.com/c0mmand3rOpSec/CVE-2017-10271'
    label: secalert_us@oracle.com
  - url: 'https://www.exploit-db.com/exploits/43458/'
    label: secalert_us@oracle.com
  - url: 'https://www.exploit-db.com/exploits/43924/'
    label: secalert_us@oracle.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/101304'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1039608'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/c0mmand3rOpSec/CVE-2017-10271'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/43458/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/43924/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-10271
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.9999
epssPercentile: 0.99985
kev: true
kevDateAdded: '2022-02-10'
kevDueDate: '2022-08-10'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-13T06:00:54.189Z'
exploits:
  exploitdb: true
  github: 29
  githubRepos:
    - 'https://github.com/1337g/CVE-2017-10271'
    - 'https://github.com/s3xy/CVE-2017-10271'
    - 'https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271'
  metasploit:
    - exploit/multi/http/oracle_weblogic_wsat_deserialization_rce
  nuclei:
    - CVE-2017-10271
  checkedAt: '2026-09-15T16:16:02.719Z'
---

## Overview

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

## Affected

- `weblogic_server = 10.3.6.0.0`
- `weblogic_server = 12.1.3.0.0`
- `weblogic_server = 12.2.1.1.0`
- `weblogic_server = 12.2.1.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
