|
|||
Rule General Information |
---|
Release Date: | 2018-07-30 | |
Rule Name: | WEB-SERVER Oracle WebLogic Server Activator Insecure Deserialization Vulnerability (CVE-2018-2893) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. | |
Impact: | Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. | |
Affected OS: | Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android | |
Reference: | http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html SecurityFocusBID:104763 SecurityTrackerID:1041301 |
|
Solutions |
---|
Please replace the product with an unaffected version. |