|
|||
Rule General Information |
---|
Release Date: | 2018-10-29 | |
Rule Name: | Oracle WebLogic Server RemoteObject Insecure Deserialization Vulnerability (CVE-2018-3245) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. | |
Impact: | Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. A remote user can exploit a flaw in the Oracle WebLogic Server WLS Core Components to gain elevated privileges. | |
Affected OS: | Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android | |
Reference: | SecurityFocusBID:105613 ExploitDB:46513 http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html SecurityTrackerID:1041896 |
|
Solutions |
---|
The vendor has issued a fix. The vendor advisory is available at: https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html |