CVE-2017-10271 is an unsafe XMLDecoder deserialization vulnerability in the WLS Security component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0. A remote, unauthenticated attacker can submit Java-class objects containing attacker-controlled content to achieve arbitrary code execution and take over the server. Exploitation has targeted WLS-WSAT endpoints and has been used to deploy cryptominers, backdoors, and other malware.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (7 hidden).
This is a deliberately vulnerable lab with documented CVE-2017-10271 exploit payloads, not a standalone automated exploit client. Unauthenticated SOAP requests to /wls-wsat/CoordinatorPortType place attacker-controlled object descriptions in WorkContext, reaching Java XMLDecoder. The walkthrough demonstrates ProcessBuilder-based command execution and PrintWriter-based JSP creation. The JSP only prints a marker despite being described as a webshell. Payload validity and successful exploitation were not tested; hardcoded paths, callback settings, and literal HTTP Content-Length values may require adjustment. The 33-file repository contains a central Isoloom specification, CTF metadata, vendored English and Chinese Vulhub walkthroughs and Compose configuration under app/, two historical Dockerfile recipes under base/, and a custom endpoint check under checks/. Generated .isoloom/ outputs support Docker, Kubernetes, a Vagrant-hosted Docker VM, Proxmox, and six cloud providers: AWS, Azure, DigitalOcean, GCP, Linode, and OCI. GitHub workflows validate the specification, generated infrastructure, and lab health, and optionally register the lab through secret-configured publishing services. Isoloom is deployment tooling, not an exploit framework. The code-file count includes seven Terraform files, one Ruby Vagrantfile, five shell scripts, and two Dockerfiles; YAML deployment and workflow configurations are counted separately from source code. XML, Bash, and JSP/Java exploit snippets are embedded in Markdown rather than standalone exploit files. Health checks establish console availability, endpoint deployment, and intended egress restrictions; they do not prove exploitability. Docker removes the WebLogic network namespace's default route, while Kubernetes uses NetworkPolicies whose enforcement depends on the cluster networking implementation. Kubernetes checks run in separate pods, so their egress probe does not directly test the WebLogic pod. Cloud ingress is restricted by allowed_cidr, whereas the Kubernetes LoadBalancer policy permits access to port 7001 from any IPv4 address. No evidence of a fake exploit or malicious analyst-directed payload was found. Destructive cleanup commands occur in CI disk reclamation and VM reprovisioning, not in the exploit payload. The original repository URL, analyzed Git reference, archive location, and archive byte size were not supplied; empty strings and zero represent unavailable repository metadata. UPSTREAM.md identifies a separate vendored Vulhub commit, 8fd63916f7a8711e2e01dda0d27237e4d6175d38.
This repository contains a Python-based exploit tool for CVE-2017-10271, a critical remote code execution vulnerability in Oracle WebLogic Server. The main file, 'CVE-2017-10271_Tool.py', is a comprehensive interactive tool that allows the user to: - Detect WebLogic servers and enumerate their versions. - Scan for the presence of the CVE-2017-10271 vulnerability. - Upload test files to the server. - Execute arbitrary system commands, including launching a reverse shell or uploading a webshell for persistent access. - Interact with a webshell via Selenium for browser-based access. The tool is menu-driven and logs all activities to a timestamped log file. It targets specific WebLogic endpoints known to be vulnerable, such as '/wls-wsat/CoordinatorPortType'. The included 'docker-compose.yml' file provides a quick way to deploy a vulnerable WebLogic instance for testing, using the 'vulhub/weblogic:10.3.6.0-2017' Docker image. Overall, the repository is well-structured for both exploitation and testing, providing detection, exploitation, and post-exploitation capabilities for CVE-2017-10271 on Oracle WebLogic Server.
This repository contains a single Metasploit module targeting Oracle WebLogic Server's wls-wsat component (CVE-2017-10271). The exploit leverages a Java XML deserialization vulnerability to achieve remote code execution (RCE) on affected WebLogic versions (10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0) on both Windows and Unix platforms. The module constructs a malicious SOAP XML payload that, when processed by the vulnerable endpoint (default: /wls-wsat/CoordinatorPortType), causes the server to execute arbitrary OS commands. The exploit is operational and allows the attacker to specify the command to run. The only file present is a Ruby script compatible with the Metasploit framework, and it is structured as a standard Metasploit exploit module. No hardcoded IPs or domains are present, but the endpoint path is fingerprintable. The module is not a detection script; it is a full exploit capable of achieving RCE if the target is vulnerable.
This repository provides a working exploit for CVE-2017-10271, a critical unauthenticated remote code execution vulnerability in Oracle WebLogic Server. The exploit targets the /wls-wsat/CoordinatorPortType SOAP endpoint, sending a specially crafted XML payload that leverages Java XMLDecoder deserialization to execute arbitrary system commands on the server. The main files are: - exploit.py: Core exploit script that takes a target URL and a command, then sends the malicious SOAP payload to the vulnerable endpoint. - payloads.py: Contains the function to generate the SOAP/XML payload for command execution. - weblogic.py: A more advanced script that reads a list of hosts, checks for the vulnerability, and attempts exploitation with a default PowerShell payload that downloads and executes a remote script. - scanner.sh: Bash script to quickly check if a host exposes the vulnerable endpoint and appears to be running WebLogic. The exploit is operational and allows the attacker to execute arbitrary commands, with the default payload designed to fetch and run a PowerShell script from a remote server. The repository also includes detection and host enumeration logic. The main attack vector is network-based, requiring access to the WebLogic SOAP endpoint. The exploit is not part of a larger framework and is implemented in Python and Bash.
This repository is a Java-based GUI tool for exploiting Oracle WebLogic Server deserialization vulnerabilities, specifically CVE-2017-10271 and CVE-2019-2725, affecting versions 10 and 12. The tool provides a graphical interface (Main.java) allowing users to check for vulnerabilities, execute arbitrary commands, upload files, and retrieve server paths on vulnerable WebLogic instances. The core logic is implemented in the 'paylaod' package, with separate classes for each CVE and WebLogic version. The tool constructs and sends crafted SOAP/XML payloads to specific WebLogic endpoints (such as /wls-wsat/CoordinatorPortType and /_async/AsyncResponseService) to trigger the vulnerabilities. The 'tools' package provides supporting utilities for HTTP requests, encoding, and other helper functions. The repository is operational, providing working exploit code with customizable payloads, and is not part of a larger exploit framework.
This repository contains a set of exploits targeting Oracle WebLogic Server's CVE-2017-10271 vulnerability, which allows unauthenticated remote code execution via a SOAP/XML deserialization flaw in the WLS Security component. The main exploit scripts are 'weblogic_wls_wsat_exp.py' (for Linux) and 'weblogic_wls_wsat_exp_win.py' (for Windows), both written in Python. These scripts craft malicious SOAP requests to the '/wls-wsat/CoordinatorPortType' endpoint, leveraging XMLDecoder deserialization to execute arbitrary system commands or upload a JSP webshell ('exec.jsp') to the server. The webshell enables further command execution via HTTP requests. The 'weblogic_check_version.py' script is included to fingerprint and determine the version of a target WebLogic server. The exploit supports both command execution with output retrieval and direct webshell upload, providing operational-level exploitation capabilities. The repository is structured with clear separation between Linux and Windows exploitation, a reusable JSP webshell, and a version checking utility.
This repository provides a comprehensive exploitation and detection toolkit for CVE-2017-10271, a critical remote code execution vulnerability in Oracle WebLogic Server's wls-wsat component. The main exploit (CVE-2017-10271.py) is a standalone Python script that can both check for vulnerability (by causing the target to make an outbound HTTP request) and exploit it (by executing a reverse shell payload for Unix or Windows). The repository also includes a Metasploit module (oracle_weblog_wsat_rce.rb) for framework-based exploitation, a Go-based scanner for bulk detection, and original proof-of-concept code. Multiple shell scripts are provided to assist with setting up listeners for reverse shells or check responses. The vulnerable endpoints are well-documented and include several /wls-wsat/* SOAP endpoints. The exploit works by sending a specially crafted SOAP XML payload to the target's vulnerable endpoint, leveraging Java deserialization to achieve arbitrary command execution. The repository is well-structured, with clear separation between exploit, detection, and setup components, and includes documentation for both setting up a vulnerable environment and using the tools provided.
This repository contains a Python exploit script (CVE-2017-10271.py) targeting Oracle WebLogic Server instances vulnerable to CVE-2017-10271, a remote code execution flaw. The exploit works by sending a specially crafted SOAP XML payload to the /wls-wsat/CoordinatorPortType endpoint of the target server. The payload leverages Java's XMLDecoder to execute arbitrary system commands via ProcessBuilder, specifically using 'cmd /c <command>' (thus, the exploit is tailored for Windows targets). The script provides an interactive shell-like interface, allowing the user to input commands that are then executed on the remote server. The README provides basic usage instructions and notes that the exploit is for Windows, but could be adapted for Linux. The repository is straightforward, with one main exploit script and a brief README.
This repository contains a proof-of-concept (POC) exploit for the Oracle WebLogic wls9-async component deserialization vulnerability (CNVD-C-2019-48814), affecting WebLogic Server versions 10.x and 12.1.3. The main exploit script, 'CNVD-C-2019-48814-poc.py', is a Python 3 tool that reads a list of target IPs from a file, sends a crafted SOAP request to the '/_async/AsyncResponseService' endpoint on each target, and checks for a 202 response code to determine vulnerability. The payload leverages Java deserialization via the WorkContext header to achieve remote code execution. The README provides detailed usage instructions and example payloads for spawning a reverse shell, uploading a webshell, and executing arbitrary commands. It also documents typical file paths for uploaded webshells and provides example SOAP payloads for different attack scenarios. The exploit is network-based, targeting accessible WebLogic HTTP endpoints, and can be used to gain full remote code execution on vulnerable servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older Oracle WebLogic Server remote code execution vulnerability referenced as still being targeted in attacks against WebLogic environments.
A critical Oracle WebLogic Server remote code execution vulnerability referred to here as WLS-WSAT RCE and observed in exploitation attempts against honeypots.
A remote code execution vulnerability in Oracle WebLogic Server used as the initial access vector against a Hungarian government-related server via a crafted SOAP request that triggered execution of a Python reverse shell.
An Oracle WebLogic XMLDecoder deserialization remote code execution flaw that remained part of the operator's toolkit and targeting workflow.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.