vendor:
WebLogic Server
by:
Ricardo J. RodrÃguez
9,8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: WebLogic Server
Affected Version From: 10.3.6.0.0
Affected Version To: 12.2.1.3.0
Patch Exists: YES
Related CWE: CVE-2018-2628
CPE: a:oracle:weblogic_server
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Remote Code Execution in Oracle WebLogic Server
This exploit allows an attacker to execute arbitrary commands on a vulnerable Oracle WebLogic Server instance. The vulnerability exists due to the lack of proper input validation in the WebLogic Server's 'CoordinatorPortType' SOAP service. An attacker can exploit this vulnerability by sending a specially crafted SOAP request containing malicious Java code to the vulnerable service. This code will be executed on the server with the privileges of the WebLogic user.
Mitigation:
Oracle has released a patch to address this vulnerability. It is recommended to apply the patch as soon as possible.