CVE-2016-0638
CRITICAL EXPLOITEDOracle WebLogic Server - Info Disclosure
Title source: llmExploitation Summary
CVE-2016-0638 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including 0xn0ne, zhzhdoai, BabyTeam1024.
AI-analyzed exploit summary This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.
Description
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Exploits (4)
This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.
This repository contains proof-of-concept exploits for multiple WebLogic vulnerabilities, including CVE-2015-4852, which leverages Java deserialization via Apache Commons Collections to achieve remote code execution. The PoC generates a serialized payload that, when deserialized, executes arbitrary commands.
This repository contains a functional exploit for CVE-2016-0638, a deserialization vulnerability in Oracle WebLogic Server. The exploit leverages the T3 protocol to achieve remote code execution (RCE) by installing an RMI backdoor and executing arbitrary commands.
This repository contains a functional exploit for CVE-2016-0638, a deserialization vulnerability in Oracle WebLogic Server's T3 protocol. The exploit leverages Apache Commons Collections gadgets to achieve remote command execution by bypassing blacklist restrictions via StreamMessageImpl or MarshalledObject wrappers.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H