CVE-2017-3506CISA KEVEPSS p99.9%

CVE-2017-3506Oracle WebLogic Server OS Command Injection Vulnerability

Oracle / WebLogic Server

Description

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

Scoring

EPSS96.02% probability of exploitation · percentile 99.9% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2024-06-03

(incoming)1

TypeTargetConfidenceTier
KEVEntryOracle WebLogic Server OS Command Injection Vulnerabilitykev-cve-2017-35060%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
CVE
Oracle WebLogic Server, Injection
CVE
Oracle WebLogic Server Remote Code Execution Vulnerability
CVE
Oracle Fusion Middleware Unspecified Vulnerability
CVE
Oracle WebLogic Server Unspecified Vulnerability
CVE
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.