CVE-2018-2628
Oracle WebLogic Server Unspecified Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
14Exploited in Wild
YesDecision
Descriptions
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Vulnerabilidad en el componente Oracle WebLogic Server de Oracle Fusion Middleware (subcomponente: WLS Core Components). Las versiones compatibles que se han visto afectadas son la 10.3.6.0, 12.1.3.0, 12.2.1.2 y la 12.2.1.3. Esta vulnerabilidad fácilmente explotable permite que un atacante sin autenticar con acceso en red via T3 comprometa la seguridad de Oracle WebLogic Server. Los ataques exitosos de esta vulnerabilidad pueden resultar en la toma de control de Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (impactos en la confidencialidad, integridad y disponibilidad). Vector CVSS: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
An unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object to the interface to execute code on vulnerable hosts.
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2017-12-15 CVE Reserved
- 2018-04-18 First Exploit
- 2018-04-19 CVE Published
- 2022-09-08 Exploited in Wild
- 2022-09-29 KEV Due Date
- 2024-10-03 CVE Updated
- 2024-10-05 EPSS Updated
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103776 | Third Party Advisory | |
http://www.securitytracker.com/id/1040696 | Third Party Advisory | |
https://github.com/brianwrf/CVE-2018-2628 | Broken Link | |
- |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46513 | 2024-10-03 | |
https://www.exploit-db.com/exploits/44553 | 2024-10-03 | |
https://www.exploit-db.com/exploits/45193 | 2024-10-03 | |
https://github.com/shengqi158/CVE-2018-2628 | 2018-07-20 | |
https://github.com/forlin/CVE-2018-2628 | 2018-04-18 | |
https://github.com/jas502n/CVE-2018-2628 | 2019-09-30 | |
https://github.com/zjxzjx/CVE-2018-2628-detect | 2018-04-20 | |
https://github.com/aedoo/CVE-2018-2628-MultiThreading | 2018-04-19 | |
https://github.com/0xMJ/CVE-2018-2628 | 2019-01-07 | |
https://github.com/Lighird/CVE-2018-2628 | 2018-10-30 | |
https://github.com/victor0013/CVE-2018-2628 | 2018-04-18 | |
https://github.com/likescam/CVE-2018-2628 | 2018-06-05 | |
https://github.com/skydarker/CVE-2018-2628 | 2018-04-18 | |
https://github.com/9uest/CVE-2018-2628 | 2018-04-19 |
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html | 2019-04-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 10.3.6.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "10.3.6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.2.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.3 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3" | - |
Affected
|