ZeroHour

CVE-2018-2628

KEV PoC ×3large

Unauthenticated Java Deserialization RCE in Oracle WebLogic Server via T3

CISA: Oracle WebLogic Server Unspecified Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2018-2628 is a deserialization flaw (CWE-502) in the WLS Core Components of Oracle WebLogic Server that can be triggered by an unauthenticated attacker simply by sending malicious data over the T3 protocol to a reachable server. Because exploitation requires no credentials or user interaction and is easy to execute, a successful attack allows complete takeover of the WebLogic server, giving the attacker full confidentiality, integrity, and availability impact (CVSS 9.8). Any WebLogic Server installation running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.2, or 12.2.1.3 is vulnerable, with internet-facing T3 endpoints at highest risk. Exploitation is well established: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-09-08), carries a 99.4% EPSS probability of exploitation, has three public exploits on Exploit-DB, and attackers have actively scanned for vulnerable WebLogic servers — including after Oracle's initial patch proved incomplete and reopened patched servers to attack.

What to do: Apply the Oracle Critical Patch Update fixes for WebLogic Server on all affected versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3), and re-verify patching against the most recent Oracle CPU since the initial fix was incomplete and left updated servers exposed. Restrict access to the T3 protocol (default port 7001) so it is reachable only from trusted hosts, and prioritize patching any T3 endpoints exposed to the internet. Search logs for suspicious T3 traffic and confirm remediation with a public exploit check.

Affected
Oracle WebLogic Server (WLS Core Components)10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3
Estimated exposure
large≈10,000–30,000 internet-exposed WebLogic servers, with a far larger internal enterprise install base — Internet-wide scans of WebLogic's T3 protocol (default port 7001) around the time of disclosure found tens of thousands of publicly reachable servers, and WebLogic's prevalence as enterprise middleware implies many more internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle WebLogic Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
weblogic server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news