Does Patch 24667634 Fix CVE-2017-3248?
Hello,
We have seen activity on a WebLogic server which I believe is an active exploitation of CVE-2017-3248. According to the CPU January 2017 Update Advisory, CVE-2017-3248 is addressed in that patch set:
Oracle Critical Patch Update - January 2017
The Update Advisory says to refer to My Oracle Support Note 2203916.1 for information on the specific patches which need to be applied:
https://support.oracle.com/rs?type=doc&id=2203916.1
We're running WebLogic 10.3.6 on Linux x86-64. The Support Note says that the patch is WLS PSU 10.3.6.0.170117 Patch 24667634 and lists CVE-2017-3248 as the "Advisory Number". However, the information for