Patch Reviews - Middleware (MOSC)

MOSC Banner

Does Patch 24667634 Fix CVE-2017-3248?

edited Mar 13, 2017 5:25PM in Patch Reviews - Middleware (MOSC) 6 commentsAnswered

Hello,

We have seen activity on a WebLogic server which I believe is an active exploitation of CVE-2017-3248.  According to the CPU January 2017 Update Advisory, CVE-2017-3248 is addressed in that patch set:

Oracle Critical Patch Update - January 2017

The Update Advisory says to refer to My Oracle Support Note 2203916.1 for information on the specific patches which need to be applied:

https://support.oracle.com/rs?type=doc&id=2203916.1

We're running WebLogic 10.3.6 on Linux x86-64.  The Support Note says that the patch is WLS PSU 10.3.6.0.170117 Patch 24667634 and lists CVE-2017-3248 as the "Advisory Number".  However, the information for

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center