KEVIntel
9.8
CVSS
Critical

CVE-2018-2628

PUBLISHED

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Oracle Corporation
Product
WebLogic Server
Published
Apr 19, 2018
EPSS

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-09-08 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Sep 08, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

weblogic_deserialize

metasploit · Created Unknown

Metasploit module for CVE-2018-2628

0xMJ/CVE-2018-2628

github · Created 2019-01-07 11:47:59 UTC · 12 stars

漏洞利用工具

Lighird/CVE-2018-2628

github · Created 2018-10-30 03:26:16 UTC · 9 stars

CVE-2018-2628漏洞工具包

likekabin/CVE-2018-2628

github · Created 2018-07-02 09:00:34 UTC · 3 stars

stevenlinfeng/CVE-2018-2628

github · Created 2018-06-26 08:25:57 UTC · 0 stars

jas502n/CVE-2018-2628

github · Created 2018-06-05 11:00:40 UTC · 104 stars

Weblogic 反序列化漏洞(CVE-2018-2628)

shaoshore/CVE-2018-2628

github · Created 2018-04-20 02:14:21 UTC · 0 stars

Shadowshusky/CVE-2018-2628all

github · Created 2018-04-20 01:24:17 UTC · 2 stars

9uest/CVE-2018-2628

github · Created 2018-04-19 15:56:49 UTC · 1 stars

victor0013/CVE-2018-2628

github · Created 2018-04-19 03:19:15 UTC · 1 stars

CVE-2018-2628

aedoo/CVE-2018-2628-MultiThreading

github · Created 2018-04-18 17:50:29 UTC · 15 stars

WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading

zjxzjx/CVE-2018-2628-detect

github · Created 2018-04-18 17:28:44 UTC · 2 stars

skydarker/CVE-2018-2628

github · Created 2018-04-18 10:50:09 UTC · 1 stars

CVE-2018-2628

shengqi158/CVE-2018-2628

github · Created 2018-04-18 05:41:23 UTC · 78 stars

CVE-2018-2628 & CVE-2018-2893

forlin/CVE-2018-2628

github · Created 2018-04-18 02:56:39 UTC · 20 stars

CVE-2018-2628

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit