CVE-2017-3506
WebLogic Web Services OS Command Injection: stopped at runtime
Waratek RASP’s secure runtime rules stop this class of attack out of the box - no application change, no vendor patch, no downtime.
Published April 24, 2017 · Updated March 18, 2026
The vulnerability
Remote code execution via WebLogic Web Services XML deserialization
An unauthenticated attacker with HTTP access to Oracle WebLogic Server's Web Services subcomponent can send a crafted XML request that gets deserialized into an OS command, letting them execute arbitrary commands on the underlying server. The 8220 Gang has used this flaw for years to install cryptomining malware on unpatched, internet-facing WebLogic servers.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP applies a secure runtime rule that covers this whole class of attack out of the box - the exploit is stopped inside the JVM before it ever reaches a dangerous sink.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| WebLogic Web Services OS Command Injection protectionCVE-2017-3506 · OS command injection | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
WebLogic Web Services OS Command Injection FAQ
Is WebLogic Web Services OS Command Injection (CVE-2017-3506) exploitable?
CVE-2017-3506 carries a CVSS 7.4/10 (HIGH) rating and affects Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, and 12.2.1.2. An unauthenticated attacker with HTTP access to Oracle WebLogic Server's Web Services subcomponent can send a crafted XML request that gets deserialized into an OS command, letting them execute arbitrary commands on the underlying server. The 8220 Gang has used this flaw for years to install cryptomining malware on unpatched, internet-facing WebLogic servers. It is listed in CISA's Known Exploited Vulnerabilities catalog.
How does Waratek mitigate WebLogic Web Services OS Command Injection (CVE-2017-3506)?
Waratek RASP blocks exploitation of WebLogic Web Services OS Command Injection (CVE-2017-3506) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
How quickly was WebLogic Web Services OS Command Injection (CVE-2017-3506) exploited after disclosure?
A working exploit for CVE-2017-3506 appeared within 926 days of its NVD disclosure, on November 5, 2019.
Protect your apps in production
Get protected against WebLogic Web Services OS Command Injection - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2017-3506 and attacks like it, and get you covered in production.