CVE-2018-2628
KEV PoC ×3largeUnauthenticated Java Deserialization RCE in Oracle WebLogic Server via T3
CISA: Oracle WebLogic Server Unspecified Vulnerability
CVE-2018-2628 is a deserialization flaw (CWE-502) in the WLS Core Components of Oracle WebLogic Server that can be triggered by an unauthenticated attacker simply by sending malicious data over the T3 protocol to a reachable server. Because exploitation requires no credentials or user interaction and is easy to execute, a successful attack allows complete takeover of the WebLogic server, giving the attacker full confidentiality, integrity, and availability impact (CVSS 9.8). Any WebLogic Server installation running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.2, or 12.2.1.3 is vulnerable, with internet-facing T3 endpoints at highest risk. Exploitation is well established: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-09-08), carries a 99.4% EPSS probability of exploitation, has three public exploits on Exploit-DB, and attackers have actively scanned for vulnerable WebLogic servers — including after Oracle's initial patch proved incomplete and reopened patched servers to attack.
What to do: Apply the Oracle Critical Patch Update fixes for WebLogic Server on all affected versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3), and re-verify patching against the most recent Oracle CPU since the initial fix was incomplete and left updated servers exposed. Restrict access to the T3 protocol (default port 7001) so it is reachable only from trusted hosts, and prioritize patching any T3 endpoints exposed to the internet. Search logs for suspicious T3 traffic and confirm remediation with a public exploit check.
| Oracle WebLogic Server (WLS Core Components) | 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected
- Oracle WebLogic Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- weblogic server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H