CVE-2019-2618

MEDIUM EXPLOITED

Oracle WebLogic Server <12.2.1.3 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-2618 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including 0xn0ne, dr0op, jas502n.

AI-analyzed exploit summary This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).

Exploits (7)

nomisec SCANNER 2,072 stars
by 0xn0ne · remote-auth
https://github.com/0xn0ne/weblogicScanner

This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server · Python 3.6 or higher
devstral-2 · analyzed Feb 15, 2026 Full analysis →
nomisec SCANNER 968 stars
by dr0op · remote
https://github.com/dr0op/WeblogicScan

This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2019-2618. It is a detection tool rather than an exploit, as it only verifies the presence of vulnerabilities without executing payloads for exploitation.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 173 stars
by jas502n · remote-auth
https://github.com/jas502n/cve-2019-2618

This repository contains a functional Python exploit for CVE-2019-2618, a WebLogic Server vulnerability allowing authenticated users to upload malicious JSP files for remote code execution. The PoC includes detailed HTTP request examples and a script to automate the exploit.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6.0
Auth required
Prerequisites: Valid WebLogic credentials · Network access to the WebLogic Server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 54 stars
by pyn3rd · poc
https://github.com/pyn3rd/CVE-2019-2618

This repository contains a functional exploit for CVE-2019-2618, a deserialization vulnerability in Oracle WebLogic Server. The PoC demonstrates remote code execution (RCE) by uploading a malicious JSP file via a crafted HTTP POST request to the DeploymentService endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6.0
Auth required
Prerequisites: Network access to the WebLogic Server · Valid credentials (weblogic/weblogic)
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by he1dan · remote
https://github.com/he1dan/cve-2019-2618

This exploit targets CVE-2019-2618, a deserialization vulnerability in Oracle WebLogic Server. It attempts to upload a malicious JSP shell by exploiting the deployment service endpoint with crafted multipart/form-data requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6.0
Auth required
Prerequisites: Network access to the WebLogic Server deployment service endpoint · Valid credentials for authentication
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by wsfengfan · poc
https://github.com/wsfengfan/CVE-2019-2618-

This repository contains a functional exploit PoC for CVE-2019-2618, a vulnerability in Oracle WebLogic Server that allows unauthenticated file upload leading to remote code execution. The script crafts a malicious multipart/form-data request to upload a JSP file to a vulnerable endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
Auth required
Prerequisites: Target WebLogic Server instance · Valid credentials for authentication
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by ianxtianxt · remote-auth
https://github.com/ianxtianxt/cve-2019-2618

This Python script exploits CVE-2019-2618, a vulnerability in Oracle WebLogic Server, by uploading a malicious JSP file to achieve remote code execution. The exploit uses a multipart/form-data POST request to upload a shell.jsp file to a vulnerable endpoint, bypassing authentication checks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
Auth required
Prerequisites: Valid WebLogic credentials · Network access to the WebLogic Server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.3341
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2024-05-22
Status published
Products (3)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
Published Apr 23, 2019
Tracked Since Feb 18, 2026