CVE-2016-0638
published 2016-04-21CVE-2016-0638: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to…
PriorityP189critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
62.92%
99.1th percentile
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
rule generic_jsp
{
meta:
description = "Generic JSP"
family = "JSP Backdoor"
filetype = "JSP"
hash = "6517e4c8f19243298949711b48ae2eb0b6c764235534ab29603288bc5fa2e158"
strings:
$exec = /Runtime.getRuntime\(\).exec\(request.getParameter\(\"[a-zA-Z0-9]+\"\)\);/ ascii
condition:
all of them
}- →CVE-2016-0638 bypasses the CVE-2015-4852 blacklist by routing deserialization through weblogic.jms.common.StreamMessageImpl's readExternal(), which uses a PayloadStream (an ObjectInputStream subclass) not covered by the blacklist. ↗
- →The bypass exploits classes whose readObject()/readExternal() methods accept an InputStream and wrap it in a new ObjectInputStream, circumventing the ServerChannelInputStream/MsgAbbrevInputStream blacklist check. ↗
- →Use YARA filesystem scanning (e.g., via Nessus file system scanner) to hunt for JSP web shells dropped after WebLogic exploitation; the generic_jsp rule targets Runtime.getRuntime().exec(request.getParameter(...)) patterns. ↗
- ·JSP web shells dropped via this exploit have very low AV detection rates (2/54 observed), making AV an unreliable sole detection control; filesystem YARA scanning is recommended. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hhg5-g8w6-h56h: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14
CVE-2016-0638 [CRITICAL] GHSA-hhg5-g8w6-h56h: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
VulnCheck
Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization
vulncheck·2016·CVSS 9.8
CVE-2016-0638 [CRITICAL] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization
Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Affected: Oracle WebLogic Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era/
Exploit PoC: https://vulncheck.com/xdb/0a9deb08c929; https://vulncheck.com/xdb/681ebe30d45c
No detection rules found.
No public exploits indexed.
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20·CVSS 9.8
[CRITICAL] Hunting for Web Shells
Blog /
Subscribe
# Hunting for Web Shells
Jacob Baines
December 20, 2016
10 Min Read
Web shells are nothing new, but their use continues to plague security professionals and their customers. With low anti-virus detection rates and few good tools to aid in discovery, how can you fight back?
### A breach has occurred
On November 25th, 900 San Francisco Municipal Transportation Agency (SFMTA) computers were infected by a ransomware variant known as HDDCryptor. The ransom demand was 100 bitcoins (approximately $73,000). Due to the attack the SFMTA was temporarily unable to collect an estimated $50,000 in fares.
"You Hacked, ALL Data Encrypted, Contact For Key([email protected])ID:601, Enter Key:"
The immediate question is: “How did this happen?” In a press release, the SFMTA stated th
Tenable
Hunting for Web Shells
blogs_tenable·2016-12-20
Hunting for Web Shells
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R1] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization Remote Code Execution
blogs_tenable·2016-04-19
[R1] Oracle WebLogic ClassFilter.class ServerChannelInputStream Bypass Java Deserialization Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2016-1658 chromium-browser: potential leak of sensitive information to malicious extensions
bugzilla·2016-04-14·CVSS 4.3
CVE-2016-1658 [MEDIUM] CVE-2016-1658 chromium-browser: potential leak of sensitive information to malicious extensions
CVE-2016-1658 chromium-browser: potential leak of sensitive information to malicious extensions
Potential leak of sensitive information to malicious extensions.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=573317
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1654 chromium-browser: uninitialized memory read in media
bugzilla·2016-04-14·CVSS 6.5
CVE-2016-1654 [MEDIUM] CVE-2016-1654 chromium-browser: uninitialized memory read in media
CVE-2016-1654 chromium-browser: uninitialized memory read in media
A uninitialized memory read flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=589512
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1653 chromium-browser: out-of-bounds write in V8
bugzilla·2016-04-14·CVSS 8.8
CVE-2016-1653 [HIGH] CVE-2016-1653 chromium-browser: out-of-bounds write in V8
CVE-2016-1653 chromium-browser: out-of-bounds write in V8
A out-of-bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=589792
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1659 chromium-browser: various fixes from internal audits
bugzilla·2016-04-14·CVSS 9.8
CVE-2016-1659 [CRITICAL] CVE-2016-1659 chromium-browser: various fixes from internal audits
CVE-2016-1659 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=602697
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1652 chromium-browser: universal XSS in extension bindings
bugzilla·2016-04-14·CVSS 6.1
CVE-2016-1652 [MEDIUM] CVE-2016-1652 chromium-browser: universal XSS in extension bindings
CVE-2016-1652 chromium-browser: universal XSS in extension bindings
A universal xss flaw was found in the extension bindings component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=590275
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1655 chromium-browser: use-after-free related to extensions
bugzilla·2016-04-14·CVSS 8.8
CVE-2016-1655 [HIGH] CVE-2016-1655 chromium-browser: use-after-free related to extensions
CVE-2016-1655 chromium-browser: use-after-free related to extensions
Use-after-free related to extensions.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=582008
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1651 chromium-browser: out-of-bounds read in Pdfium JPEG2000 decoding
bugzilla·2016-04-14·CVSS 8.1
CVE-2016-1651 [HIGH] CVE-2016-1651 chromium-browser: out-of-bounds read in Pdfium JPEG2000 decoding
CVE-2016-1651 chromium-browser: out-of-bounds read in Pdfium JPEG2000 decoding
A out-of-bounds read flaw was found in the Pdfium JPEG2000 decoding component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=591785
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1656 chromium-browser: android downloaded file path restriction bypass
bugzilla·2016-04-14·CVSS 7.5
CVE-2016-1656 [HIGH] CVE-2016-1656 chromium-browser: android downloaded file path restriction bypass
CVE-2016-1656 chromium-browser: android downloaded file path restriction bypass
Android downloaded file path restriction bypass.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=570750
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
Bugzilla
CVE-2016-1657 chromium-browser: address bar spoofing
bugzilla·2016-04-14·CVSS 4.3
CVE-2016-1657 [MEDIUM] CVE-2016-1657 chromium-browser: address bar spoofing
CVE-2016-1657 chromium-browser: address bar spoofing
Address bar spoofing.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=567445
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0638 https://rhn.redhat.com/errata/RHSA-2016-0638.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securitytracker.com/id/1035615https://www.tenable.com/security/research/tra-2016-09http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securitytracker.com/id/1035615https://www.tenable.com/security/research/tra-2016-09
2016-04-21
Published
Exploited in the wild