CVE-2018-2893
published 2018-07-18CVE-2018-2893: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are…
PriorityP192critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
71.20%
99.3th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
otherStreamMessageImpl cannot be cast to weblogic
bytes
t3 12.2.1\nAS:255\nHL:19\nMS:10000000\nPU:t3://us-l-breens:7001
bytes
000005c3016501ffffffffffffffff0000006a0000ea600000001900937b484a56fa4a777666f581daa4f5b90e2aebfc607499b4027973720078720178720278700000000a000000030000000000000006007070707070700000000a000000030000000000000006007006fe010000aced00057372001d7765626c6f6769632e726a766d2e436c6173735461626c65456e7472792f52658157f4f9ed0c000078707200247765626c6f6769632e636f6d6d6f6e2e696e7465726e616c2e5061636b616765496e666fe6f723e7b8ae1ec9
snort
alert tcp any any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Oracle WebLogic Deserialization (CVE-2018-2893)"; flow:established,to_server; content:"t3|20|12"; depth:5; fast_pattern; content:"AS|3a|255"; distance:0; content:"HL|3a|19"; distance:0; content:"MS|3a|10000000"; distance:0; content:"PU|3a|t3|3a|//"; distance:0; reference:cve,2018-2893; reference:url,github.com/pyn3rd/CVE-2018-2893; classtype:attempted-admin; sid:2025929; rev:3; metadata:affected_product Web_Server_Applications, attack_target Server, created_at 2018_08_01, cve CVE_2018_2893, deployment Datacenter, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_05_21;)
- →Exploit traffic uses the T3 protocol; detect by matching the T3 handshake banner pattern 't3|20|12' at depth 5, followed by AS:255, HL:19, MS:10000000, and PU:t3:// fields in the same TCP stream directed to WebLogic listeners (default port 7001).
- →A vulnerable WebLogic server responding to the exploit probe will return a response containing the string 'StreamMessageImpl cannot be cast to weblogic', which can be used as a positive confirmation matcher.
- →The exploit sends a multi-stage TCP payload beginning with a T3 handshake followed by serialized Java object data (hex-encoded) over the T3 protocol; the serialized stream starts with the magic bytes 'aced0005' (Java serialization header) embedded within the larger T3 payload.
- →Shodan and FOFA queries can identify exposed Oracle WebLogic instances for asset discovery: Shodan 'product:"oracle weblogic"' or FOFA/Google 'title="oracle peoplesoft sign-in"'.
- →Exploitation was observed in the wild as early as July 21, 2018 — only 4 days after the July 17 patch — so unpatched WebLogic servers on versions 10.3.6.0, 12.1.3.0, 12.2.1.2, and 12.2.1.3 should be treated as actively targeted. ↗
- ·The Nuclei template probe uses a hardcoded internal hostname ('us-l-breens') in the T3 PU field; real attacker payloads will use their own callback host, so detections should not rely on matching this specific hostname.
- ·Reports surfaced suggesting ways to bypass the July 2018 Oracle patch; defenders should verify patch level and not assume patched systems are fully protected until Oracle confirms. ↗
- ·The Nuclei template targets both the default hostname port and explicitly port 7001; environments running WebLogic on non-standard ports may not be covered by default detection rules.
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7h6c-94v2-f6xx: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components)
ghsa_unreviewed·2022-05-13
CVE-2018-2893 [CRITICAL] GHSA-7h6c-94v2-f6xx: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle WebLogic Server Core Components T3 Network Access Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-2893 [CRITICAL] Oracle WebLogic Server Core Components T3 Network Access Vulnerability
Oracle WebLogic Server Core Components T3 Network Access Vulnerability
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected: Oracle WebLogic Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mi
Suricata
ET WEB_SPECIFIC_APPS Oracle WebLogic Deserialization (CVE-2018-2893)
suricata·2018-08-01·CVSS 9.8
CVE-2018-2893 [CRITICAL] ET WEB_SPECIFIC_APPS Oracle WebLogic Deserialization (CVE-2018-2893)
ET WEB_SPECIFIC_APPS Oracle WebLogic Deserialization (CVE-2018-2893)
Rule: alert tcp any any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Oracle WebLogic Deserialization (CVE-2018-2893)"; flow:established,to_server; content:"t3|20|12"; depth:5; fast_pattern; content:"AS|3a|255"; distance:0; content:"HL|3a|19"; distance:0; content:"MS|3a|10000000"; distance:0; content:"PU|3a|t3|3a|//"; distance:0; reference:cve,2018-2893; reference:url,github.com/pyn3rd/CVE-2018-2893; classtype:attempted-admin; sid:2025929; rev:3; metadata:affected_product Web_Server_Applications, attack_target Server, created_at 2018_08_01, cve CVE_2018_2893, deployment Datacenter, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_05_21;)
Nuclei
Oracle WebLogic Server - Remote Code Execution
nuclei·CVSS 9.8
CVE-2018-2893 [CRITICAL] Oracle WebLogic Server - Remote Code Execution
Oracle WebLogic Server - Remote Code Execution
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server.
Template:
id: CVE-2018-2893
info:
name: Oracle WebLogic Server - Remote Code Execution
author: milo2012
severity: critical
description: |
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server.
impact: |
Successful exploi
Tenable
August Vulnerability of the Month: Critical Vulnerability in Oracle WebLogic Targeted by Attackers
blogs_tenable·2018-08-30·CVSS 9.8
CVE-2018-2893 [CRITICAL] August Vulnerability of the Month: Critical Vulnerability in Oracle WebLogic Targeted by Attackers
Blog / Research
Subscribe
# August Vulnerability of the Month: Critical Vulnerability in Oracle WebLogic Targeted by Attackers
Tenable Research
August 30, 2018
3 Min Read
In August, Tenable Research voted to highlight CVE-2018-2893 in Oracle WebLogic Server because it was almost immediately exploited by multiple threat actors.
Novelty, sophistication or just plain weirdness are some of the potential criteria we use to select the Tenable vulnerability of the month. We collect nominations from our 70+ research team members, shortlist the finalists and give the entire team the chance to vote – combining the total experience and knowledge of Tenable Research to identify the vulnerability of the month.
### Background
CVE-2018-2893 caught our researchers’ attention this month. It allows
Tenable
August Vulnerability of the Month: Critical Vulnerability in Oracle WebLogic Targeted by Attackers
blogs_tenable·2018-08-30
August Vulnerability of the Month: Critical Vulnerability in Oracle WebLogic Targeted by Attackers
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104763http://www.securitytracker.com/id/1041301http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104763http://www.securitytracker.com/id/1041301
2018-07-18
Published
Exploited in the wild