RULE(RULE ID:333526)

Rule General Information
Release Date: 2021-05-08
Rule Name: WebLogic T3 Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: WebLogic is a Java-based application server developed by Oracle Corporation. It is part of the Oracle Fusion Middleware family and provides a platform for building, deploying, and managing enterprise-level applications. WebLogic is susceptible to a deserialization vulnerability, where malicious attackers can exploit the T3 protocol for network access and send deserialized data. Successful exploitation of this vulnerability can lead to arbitrary command execution. This rule is designed to detect probing behavior to determine if the T3 protocol is enabled on the target website.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.