Junglewise Threat Intelligence

CVE-2018-2628: Oracle WebLogic Server Unspecified Vulnerability

CVE-2018-2628 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-09-08

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains a deserialization vulnerability in the WLS Core Components. An unauthenticated attacker with network access via the T3 protocol can exploit this flaw to achieve a complete takeover of the server.

Affected products

  • Oracle WebLogic Server 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3

Timeline

  • 2018-04-17: advisory: Initial Oracle Critical Patch Update (CPU) advisory published.
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog.

Related threats