ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Faulty Patch for Oracle WebLogic Flaw Opens Updated Servers to Hackers Again

criticalVulnerabilityimportance 60CVE-2018-2628

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-2628
Unauthenticated Java Deserialization RCE in Oracle WebLogic Server via T3

CVE-2018-2628 is a deserialization flaw (CWE-502) in the WLS Core Components of Oracle WebLogic Server that can be triggered by an unauthenticated attacker simply by sending malicious data over the T3 protocol to a reachable server. Because exploitation requires no credentials or user interaction and is easy to execute, a successful attack allows complete takeover of the WebLogic server, giving the attacker full confidentiality, integrity, and availability impact (CVSS 9.8). Any WebLogic Server installation running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.2, or 12.2.1.3 is vulnerable, with internet-facing T3 endpoints at highest risk. Exploitation is well established: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-09-08), carries a 99.4% EPSS probability of exploitation, has three public exploits on Exploit-DB, and attackers have actively scanned for vulnerable WebLogic servers — including after Oracle's initial patch proved incomplete and reopened patched servers to attack.

Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server on all affected versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3), and re-verify patching against the most recent Oracle CPU since the initial fix was incomplete and left updated servers exposed. Restrict access to the T3 protocol (default port 7001) so it is reachable only from trusted hosts, and prioritize patching any T3 endpoints exposed to the internet. Search logs for suspicious T3 traffic and confirm remediation with a public exploit check.

9.899% KEV PoC ×3
  • Oracle WebLogic Server (WLS Core Components) 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3
large≈10,000–30,000 internet-exposed WebLogic servers, with a far larger internal enterprise install base
Full article340 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalApr 30, 2018

Earlier this month, Oracle patched a highly critical Java deserialization remote code execution vulnerability in its WebLogic Server component of Fusion Middleware that could allow attackers to easily gain complete control of a vulnerable server.

However, a security researcher, who operates through the Twitter handle @pyn3rd and claims to be part of the Alibaba security team, has now found a way using which attackers can bypass the security patch and exploit the WebLogic vulnerability once again.

WebLogic Server acts as a middle layer between the front end user interface and the backend database of a multi-tier enterprise application. It provides a complete set of services for all components and handles details of the application behavior automatically.

Initially discovered in November last year by Liao Xinxi of NSFOCUS security team, the Oracle WebLogic Server flaw (CVE-2018-2628) can be exploited with network access over TCP port 7001.

If exploited successfully, the flaw could allow a remote attacker to completely take over a vulnerable Oracle WebLogic Server. The vulnerability affects versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.

Since a proof-of-concept (PoC) exploit for the original Oracle WebLogic Server vulnerability has already been made public on Github and someone has just bypassed the patch as well, your up-to-date services are again at risk of being hacked.

Although @pyn3rd has only released a short GIF (video) as a proof-of-concept (PoC) instead of releasing full bypass code or any technical details, it would hardly take a few hours or days for skilled hackers to figure out a way to achieve same.

Currently, it is unclear when Oracle would release a new security update to address this issue that has re-opened CVE-2018-2628 flaw.

In order to be at least one-step safer, it is still advisable to install April patch update released by Oracle, if you haven't yet because attackers have already started scanning the Internet for vulnerable WebLogic servers.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/04/oracle-weblogic-rce-exploit.html