Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-2628

KEV EPSS 94.42% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-2628

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle Fusion Middleware 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle WebLogic Server是美国甲骨文(Oracle)公司的一款适用于云环境和传统环境的应用服务器,它提供了一个现代轻型开发平台,支持应用从开发到生产的整个生命周期管理,并简化了应用的部署和管理。WLS Core是其中的一个核心组件。 Oracle WebLogic Server中的WLS核心组件存在远程代码执行漏洞。攻击者可通过远程发送攻击数据,借助T3协议在WebLogic Server中执行反序列化操作利用该漏洞执行代码。以下版本受到影响:Oracle WebLogic Serve
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
Oracle CorporationWebLogic Server 10.3.6.0 -

II. Public POCs for CVE-2018-2628

#POC DescriptionSource LinkShenlong Link
1CVE-2018-2628https://github.com/forlin/CVE-2018-2628POC Details
2CVE-2018-2628 & CVE-2018-2893https://github.com/shengqi158/CVE-2018-2628POC Details
3CVE-2018-2628https://github.com/skydarker/CVE-2018-2628POC Details
4Nonehttps://github.com/jiansiting/weblogic-cve-2018-2628POC Details
5Nonehttps://github.com/zjxzjx/CVE-2018-2628-detectPOC Details
6WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreadinghttps://github.com/aedoo/CVE-2018-2628-MultiThreadingPOC Details
7CVE-2018-2628https://github.com/victor0013/CVE-2018-2628POC Details
8Nonehttps://github.com/9uest/CVE-2018-2628POC Details
9Nonehttps://github.com/Shadowshusky/CVE-2018-2628allPOC Details
10Nonehttps://github.com/shaoshore/CVE-2018-2628POC Details
11Some codes for bypassing Oracle WebLogic CVE-2018-2628 patchhttps://github.com/tdy218/ysoserial-cve-2018-2628POC Details
12Nonehttps://github.com/R0B1NL1N/CVE-2018-2628POC Details
13cve-2018-2628 反弹shellhttps://github.com/wrysunny/cve-2018-2628POC Details
14Weblogic 反序列化漏洞(CVE-2018-2628)https://github.com/jas502n/CVE-2018-2628POC Details
15Nonehttps://github.com/stevenlinfeng/CVE-2018-2628POC Details
16Nonehttps://github.com/likescam/CVE-2018-2628POC Details
17A remote code execution exploit for WebLogic based on CVE-2018-2628https://github.com/Nervous/WebLogic-RCE-exploitPOC Details
18CVE-2018-2628漏洞工具包https://github.com/Lighird/CVE-2018-2628POC Details
19漏洞利用工具https://github.com/0xMJ/CVE-2018-2628POC Details
20漏洞复现https://github.com/seethen/cve-2018-2628POC Details
21Nonehttps://github.com/BabyTeam1024/cve-2018-2628POC Details
22weblogic-cve-2018-2628-exphttps://github.com/cscadoge/weblogic-cve-2018-2628POC Details
23CVE-2018-2628漏洞工具https://github.com/Serendipity-Lucky/CVE-2018-2628POC Details
24Nonehttps://github.com/likekabin/CVE-2018-2628POC Details
25The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contains an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server. https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2018/CVE-2018-2628.yamlPOC Details
26Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Weblogic%20WLS%20Core%20Components%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2018-2628.mdPOC Details
27https://github.com/vulhub/vulhub/blob/master/weblogic/CVE-2018-2628/README.mdPOC Details
28在python3中运行的脚本https://github.com/herantong/CVE-2018-2628POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-2628

登录查看更多情报信息。

Same Patch Batch · Oracle Corporation · 2018-04-19 · 136 CVEs total

CVE-2018-2826Oracle Java SE 安全漏洞
CVE-2018-2843Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2842Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2841Oracle Database Server Java VM组件安全漏洞
CVE-2018-2840Oracle Retail Applications Retail Xstore Point of Service组件安全漏洞
CVE-2018-2839Oracle MySQL Server组件安全漏洞
CVE-2018-2838Oracle PeopleSoft Products PeopleSoft Enterprise PRTL Interaction Hub组件安全漏洞
CVE-2018-2837Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2836Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2835Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2834Oracle Fusion Middleware Data Visualization Desktop组件安全漏洞
CVE-2018-2833Oracle Hospitality Applications Hospitality Simphony组件安全漏洞
CVE-2018-2832Oracle GoldenGate组件安全漏洞
CVE-2018-2830Oracle Virtualization VM VirtualBox组件安全漏洞
CVE-2018-2829Oracle Hospitality Applications Hospitality Simphony组件安全漏洞
CVE-2018-2828Oracle Fusion Middleware WebCenter Content组件安全漏洞
CVE-2018-2827Oracle Hospitality Applications Hospitality Suite8组件安全漏洞
CVE-2018-2816Oracle MySQL Server组件安全漏洞
CVE-2018-2814Oracle Java SE和Java SE Embedded组件安全漏洞
CVE-2018-2815Oracle Java SE、Java SE Embedded和JRockit组件安全漏洞

Showing top 20 of 136 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-2628

No comments yet


Leave a comment