Vulnerability threat dossier

CVE-2017-10271

oracleweblogic server

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

VTP deterministic threat62.0of 100 · CVSS excluded

VTP analyst assessment

Monitoring — no AI review currently required

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateNOT REQUIRED
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factKEV

Assessment

This CVE remains in monitoring. Its metadata and source evidence are available below. A new material report or relevant sensor finding can trigger an AI review.

Why it matters

The available facts and source references are listed below. No AI assessment has been recorded for this dossier.

Evidence

No validated baseline evidence scope is persisted for this CVE.

Uncertainties

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

A validated functional exploit or automated exploitation capability would materially change this assessment.

AI baseline history (0)
    Technical severityHIGHCVSS 7.5 · technical context
    Public exploitationKEVGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSS1.00100th percentile · prediction
    Evidence confidence95%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
    Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      CISA KEV lists this vulnerability as known to be exploited globally.

    2. 02

      EPSS is 1.00; this is predictive context, not exploitation evidence.

    3. 03

      First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

    02

    Material change ledger

    What changed

    KEV ADDEDCISA KEV entry added
    03

    Claim provenance

    Evidence and source independence

    2publications detected
    2underlying evidence chains

    1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
    95%claim confidence
    INDEPENDENTcatalog:enisa-eu-kev:CVE-2017-10271ACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 00:0010 Feb
      KEV ADDED

      CISA KEV entry added

      CISA lists global known exploitation. This is not a VTP sensor observation.

    2. 00:0010 Feb
      ACTIVE EXPLOITATION

      ENISA EU KEV entry added

      ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

    05

    Original publications

    Source record

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

    CVE-2017-10271CVE-2020-14882CVE-2020-2551CVE-2026-21962
    Separate evidence group
    Original

    ENISA EU KEV catalog membership for CVE-2017-10271

    ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

    CVE-2017-10271
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score62.0vtp-threat-v1-public
    Public exploitation30 / 30
    EPSS prediction20 / 20
    Exploit availability2.5 / 15
    Source independence7.5 / 15
    Intelligence recency2 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    7.5 · HIGH
    Vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    CWE
    CWE-306
    CPE records
    4
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.