cbcvebase.
CVE-2018-3245
published 2018-10-17

CVE-2018-3245: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are…

PriorityP186critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
94.28%
99.8th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

6 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

otherT3
processysoserial.payloads.JRMPClient_20180718_bypass01
otherReferenceWrapper_Stub
  • Exploit targets Oracle WebLogic Server via T3 protocol deserialization; monitor for unexpected T3 protocol connections to WebLogic listener ports (default 7001/7002)
  • Exploit uses JRMP reverse-connect technique (JRMPClient bypass) via ysoserial payload; detect outbound RMI/JRMP connections initiated from the WebLogic server process after receiving a T3 request
  • Payload leverages com.sun.jndi.rmi.registry.ReferenceWrapper_Stub and sun.rmi.server.UnicastRef for deserialization gadget chain; inspect T3 traffic for serialized Java objects referencing these classes
  • This is a patch bypass for a prior WebLogic deserialization fix; ensure detection covers JRMPClient variant payloads, not just the original gadget chain
  • Affected versions are 10.3.6.0, 12.1.3.0, and 12.2.1.3; scope detection and patching to these specific version strings
  • ·The exploit payload uses a random port for the JRMP callback if no port is specified in the command argument, making static port-based detection unreliable for the callback channel
  • ·The ObjID used in the JRMP gadget is also randomized per execution, preventing reliable static ObjID-based signatures

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.