CVE-2017-10271

WebLogic WLS Security Deserialization RCE: stopped at runtime

Waratek RASP’s secure runtime rules stop this class of attack out of the box - no application change, no vendor patch, no downtime.

Published October 19, 2017 · Updated August 13, 2026

Blocked by secure rule HIGH CVSS 7.5 v3.1 Actively exploited

The vulnerability

Remote code execution via unauthenticated T3 protocol deserialization

An unauthenticated attacker with network access to Oracle WebLogic Server's T3 protocol can submit a crafted object that gets deserialized without validation, letting them execute arbitrary code on the server. The flaw was mass-exploited for cryptomining: one campaign enslaved more than 700 WebLogic servers to mine over $200,000 in Monero. Any product built on WebLogic, including PeopleSoft, inherits the exposure.

Affected softwareOracle WebLogic Server
Affected versions10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0
WeaknessUnsafe deserialization (CWE-306)
Published2017-10-19
SeverityHIGH · CVSS 7.5

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP applies a secure runtime rule that covers this whole class of attack out of the box - the exploit is stopped inside the JVM before it ever reaches a dangerous sink.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

WebLogic WLS Security Deserialization RCE FAQ

Is WebLogic WLS Security Deserialization RCE (CVE-2017-10271) exploitable?

CVE-2017-10271 carries a CVSS 7.5/10 (HIGH) rating and affects Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0. An unauthenticated attacker with network access to Oracle WebLogic Server's T3 protocol can submit a crafted object that gets deserialized without validation, letting them execute arbitrary code on the server. The flaw was mass-exploited for cryptomining: one campaign enslaved more than 700 WebLogic servers to mine over $200,000 in Monero. Any product built on WebLogic, including PeopleSoft, inherits the exposure. It is listed in CISA's Known Exploited Vulnerabilities catalog, with known ransomware campaign use.

How does Waratek mitigate WebLogic WLS Security Deserialization RCE (CVE-2017-10271)?

Waratek RASP blocks exploitation of WebLogic WLS Security Deserialization RCE (CVE-2017-10271) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was WebLogic WLS Security Deserialization RCE (CVE-2017-10271) exploited after disclosure?

A working exploit for CVE-2017-10271 appeared within 68 days of its NVD disclosure, on December 26, 2017.

Protect your apps in production

Get protected against WebLogic WLS Security Deserialization RCE - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2017-10271 and attacks like it, and get you covered in production.