RULE(RULE ID:321584)

Rule General Information
Release Date: 2018-08-14
Rule Name: Oracle WebLogic Unrestricted File Upload Vulnerability (CVE-2018-2894)
Severity:
CVE ID:
Rule Protection Details
Description: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
Impact: Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. These vulnerabilities affect the following supported versions: 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
SecurityFocusBID:104763
SecurityTrackerID:1041301
Solutions
Please replace the product with an unaffected version.