RULE(RULE ID:712730)

Rule General Information
Release Date: 2018-07-30
Rule Name: WEB-SERVER Oracle WebLogic Server Activator Insecure Deserialization Vulnerability (CVE-2018-2893)
Severity:
CVE ID:
Rule Protection Details
Description: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.
Impact: Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
SecurityFocusBID:104763
SecurityTrackerID:1041301
Solutions
Please replace the product with an unaffected version.