vendor:
WebLogic Server
by:
Zhiyi Zhang
9.8
CVSS
CRITICAL
Remote Code Execution
502
CWE
Product Name: WebLogic Server
Affected Version From: 10.3.6.0.0
Affected Version To: 12.2.1.3.0
Patch Exists: YES
Related CWE: CVE-2018-2893, CVE-2018-3245
CPE: a:oracle:weblogic_server
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
Oracle WebLogic Two RCE Deserialization Vulnerabilities
JRMPClient_20180718_bypass01 is a payload from ysoserial which can be used to exploit two remote code execution vulnerabilities in Oracle WebLogic. The payload uses the ReferenceWrapper_Stub class to create a remote object invocation handler which can be used to execute arbitrary code on the vulnerable server.
Mitigation:
Oracle has released a patch for this vulnerability. Users should update their Oracle WebLogic server to the latest version.