CVE-2018-3245
published 2018-10-17CVE-2018-3245: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are…
PriorityP186critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
94.28%
99.8th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Oracle WebLogic Server via T3 protocol deserialization; monitor for unexpected T3 protocol connections to WebLogic listener ports (default 7001/7002) ↗
- →Exploit uses JRMP reverse-connect technique (JRMPClient bypass) via ysoserial payload; detect outbound RMI/JRMP connections initiated from the WebLogic server process after receiving a T3 request ↗
- →Payload leverages com.sun.jndi.rmi.registry.ReferenceWrapper_Stub and sun.rmi.server.UnicastRef for deserialization gadget chain; inspect T3 traffic for serialized Java objects referencing these classes ↗
- →This is a patch bypass for a prior WebLogic deserialization fix; ensure detection covers JRMPClient variant payloads, not just the original gadget chain ↗
- →Affected versions are 10.3.6.0, 12.1.3.0, and 12.2.1.3; scope detection and patching to these specific version strings ↗
- ·The exploit payload uses a random port for the JRMP callback if no port is specified in the command argument, making static port-based detection unreliable for the callback channel ↗
- ·The ObjID used in the JRMP gadget is also randomized per execution, preventing reliable static ObjID-based signatures ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105613http://www.securitytracker.com/id/1041896https://www.exploit-db.com/exploits/46513/http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105613http://www.securitytracker.com/id/1041896https://www.exploit-db.com/exploits/46513/
2018-10-17
Published