⚡ Exploit-DB.ai HIGH
HIGH

CVE-2015-4852

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

WebLogic T3 Java deserialization RCE — the first of many WebLogic deserialization bugs. Block T3 protocol at the firewall or apply Oracle CPU. Disable T3 if WebLogic is internet-exposed. Java deserialization remains a critical Java EE vulnerability class.

📋 Official Description

The WLS Security component in Oracle WebLogic Server allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →