# Oracle WebLogic WLS Security Component Remote Code Execution (CVE-2017-10271)

**URL:** <https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782>\
**Category:** F5 Technical Articles\
**Tags:** asm-advanced-waf, security, weblogic, cve-2017-10271\
**Created:** [December 25, 2017, 2:19pm UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782 "2017-12-25T14:19:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gal\_Goldshtein](https://avatars.discourse-cdn.com/v4/letter/g/e99b99/32.png) [@Gal\_Goldshtein](https://community.f5.com/u/Gal_Goldshtein)\
**Post date:** [December 25, 2017, 2:19pm UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/1 "2017-12-25T14:19:00Z")

</div>

In October 2017 Oracle have [published](https://www.oracle.com/technetwork/topics/security/cpuoct2017-3236626.html) a vulnerability concerning Oracle WebLogic and assigned [CVE-2017-10271](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10271) to it. Since then no public information regarding this vulnerability was available&nbsp;until a few days ago, when an analysis of the vulnerability and a Proof-of-Concept exploit were published.

The vulnerability stems from an unsafe XML deserialization using Java XMLDecoder in the CoordinatorPortType web service, which is part of the WLS Security component of WebLogic.

Attackers may send a crafted XML document to the aforementioned web service which will cause WebLogic to deserialize it and consequently allow an attacker to construct arbitrary&nbsp;Java objects and invoke their methods resulting in&nbsp;remote code execution.

 ![image_283294.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/9/9d3d674412c5bd20fe13caed930a840aafd621b8.png)

**Figure 1:** _Part of the request exploiting the vulnerability._

#### Mitigating the vulnerability with BIG-IP ASM

BIG-IP ASM customers under any supported BIG-IP version are already protected against this 0-day vulnerability, as the exploitation attempt will be detected by an existing Java&nbsp;code injection attack signature (200004174) which can be found in signature sets that include “Server Side Code Injection” attack type or “Java Servlets/JSP” System.

 ![image_283294.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/9/1/913bd690622ed1f152393731fb799055937c7182.png)

**Figure 2:** _Exploitation attempt blocked by signature id 200004174._

We will be also releasing a dedicated signature in the upcoming ASM Security Update.

---

<div class="post-metadata">

**Author:** ![urocyongroup\_30](https://avatars.discourse-cdn.com/v4/letter/u/f1d935/32.png) [@urocyongroup\_30](https://community.f5.com/u/urocyongroup_30)\
**Post date:** [January 8, 2018, 2:52pm UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/2 "2018-01-08T14:52:29Z")

</div>

We download the last signature list and added this signature but the signature that blocks our test request is 200004336 “Oracle WebLogic WLS Security component Remote Code Execution” with Last Updated date 12/26/2017. I assume this is the adopted signature to mitigate this attack.

It seems it only works for the default context root /wls-wsat/CoordinatorPortType , if we use and other context root with the same payload the signature is not triggert.

Can we have the rule body of this signature so we can make a custom one that is more generic?

---

<div class="post-metadata">

**Author:** ![JG](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@JG](https://community.f5.com/u/JG)\
**Post date:** [January 8, 2018, 11:32pm UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/3 "2018-01-08T23:32:28Z")

</div>

Or how can we set up blocking of this sig only for a virtual server quickly? Obviously there is no time for the learning period and we don’t want to touch any other traffic.

---

<div class="post-metadata">

**Author:** ![Cirrus](https://avatars.discourse-cdn.com/v4/letter/c/a9a28c/32.png) [@Cirrus](https://community.f5.com/u/Cirrus)\
**Post date:** [January 10, 2018, 12:22pm UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/4 "2018-01-10T12:22:37Z")

</div>

Also another option would be top update the weblogic in the background, wouldn’t it? Oracle Support advised us to install the latest patch, which should fix this vulnerability

---

<div class="post-metadata">

**Author:** ![MR\_Freddy](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@MR\_Freddy](https://community.f5.com/u/MR_Freddy)\
**Post date:** [January 18, 2018, 8:30am UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/5 "2018-01-18T08:30:07Z")

</div>

Is it related to LTM ?

---

<div class="post-metadata">

**Author:** ![Cirrus](https://avatars.discourse-cdn.com/v4/letter/c/a9a28c/32.png) [@Cirrus](https://community.f5.com/u/Cirrus)\
**Post date:** [January 18, 2018, 9:06am UTC](https://community.f5.com/t/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271/66782/6 "2018-01-18T09:06:57Z")

</div>

This attack signature is for the ASM module. And now your LTM Module should be not be affected, but your backend WebLogic Servers could be.
