CVE-2018-2893

CRITICAL EXPLOITED IN THE WILD NUCLEI

Oracle WebLogic Server <12.2.1.3 - RCE

Title source: llm

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (10)

nomisec WORKING POC 104 stars
by pyn3rd · remote
https://github.com/pyn3rd/CVE-2018-2893
nomisec WORKING POC 47 stars
by qianl0ng · remote-auth
https://github.com/qianl0ng/CVE-2018-2893
nomisec SUSPICIOUS 17 stars
by bigsizeme · poc
https://github.com/bigsizeme/CVE-2018-2893
nomisec WORKING POC 13 stars
by jas502n · remote
https://github.com/jas502n/CVE-2018-2893
nomisec WORKING POC
by ianxtianxt · remote
https://github.com/ianxtianxt/CVE-2018-2893
nomisec WORKING POC
by artofwar344 · remote-auth
https://github.com/artofwar344/CVE-2018-2893
nomisec WORKING POC
by Draven996 · poc
https://github.com/Draven996/CVE-2018-2893
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner
vulncheck_xdb WORKING POC
remote
https://github.com/sry309/CVE-2018-2893

Nuclei Templates (1)

Oracle WebLogic Server - Remote Code Execution
CRITICALby milo2012
Shodan: product:"oracle weblogic" || http.title:"oracle peoplesoft sign-in"
FOFA: title="oracle peoplesoft sign-in"

Scores

CVSS v3 9.8
EPSS 0.9428
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2018-07-20
InTheWild.io 2018-07-26
Status published
Products (4)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.2.0
oracle/weblogic_server 12.2.1.3
Published Jul 18, 2018
Tracked Since Feb 18, 2026